PHP Object Injection Vulnerability in Original Theme by WordPress
CVE-2026-66568
9.8CRITICAL
What is CVE-2026-66568?
The Original Theme for WordPress has a vulnerability that allows unauthenticated attackers to exploit PHP Object Injection. This issue affects versions up to and including 1.9.0, enabling potential unauthorized access and manipulation of object properties. Users of the theme are advised to review their installations and apply necessary updates to mitigate risks associated with this vulnerability.
Affected Version(s)
Original <= 1.9.0