Unauthenticated PHP Object Injection in Education Center by WordPress
CVE-2026-66483
9.8CRITICAL
What is CVE-2026-66483?
A critical security flaw allows unauthenticated users to exploit PHP Object Injection in the Education Center theme versions 3.6.12 and earlier. This vulnerability can lead to remote code execution and unauthorized access, making it essential for users to upgrade to patched versions to safeguard their websites.
Affected Version(s)
Education Center <= 3.6.12