Unauthenticated PHP Object Injection in FreightCo Theme by WordPress
CVE-2026-66650
9.8CRITICAL
What is CVE-2026-66650?
The FreightCo theme for WordPress has a security flaw allowing unauthenticated PHP object injection. This vulnerability affects versions 1.1.15 and below, enabling potential attackers to exploit the flaw and execute arbitrary code, potentially leading to a complete compromise of the affected website. Proper precautions and updates are essential to mitigate these risks.
Affected Version(s)
FreightCo <= 1.1.15