Unauthenticated PHP Object Injection in Jacqueline Theme by WordPress
CVE-2026-78531

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-78531?

An unauthenticated PHP Object Injection vulnerability exists in Jacqueline Theme versions up to 2.22, which could allow unauthenticated attackers to exploit the vulnerability, potentially leading to arbitrary code execution or manipulation of site behavior. It is crucial for users of this theme to take immediate action to secure their websites against potential exploitation.

Affected Version(s)

Jacqueline <= 2.22

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds | Patchstack Bug Bounty Program
.