PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66565 axiomthemes CVE debrief

A critical vulnerability was found in the FC United WordPress theme, version 1.1.1 or earlier. This vulnerability allows unauthenticated PHP object injection, which could potentially lead to severe consequences.

Vendor
axiomthemes
Product
FC United
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders and security teams responsible for WordPress installations, particularly those using the FC United theme version 1.1.1 or earlier, should assess exposure and prioritize remediation efforts.

Why it matters

CVE-2026-66565 is a critical vulnerability in the FC United WordPress theme that allows unauthenticated PHP object injection. Defenders and security teams should assess exposure, prioritize remediation efforts, and verify compensating controls to mitigate potential consequences.

  • Potential for severe consequences due to unauthenticated PHP object injection
  • Requires verification of exposure and remediation efforts
  • May impact WordPress installations using the FC United theme

Technical summary

The FC United WordPress theme, version 1.1.1 or earlier, is vulnerable to unauthenticated PHP object injection. This vulnerability is tracked under CVE-2026-66565 and has a critical CVSS score of 9.8.

Defensive priority

High priority should be given to assessing exposure and applying remediation, as the vulnerability has a critical CVSS score of 9.8.

Recommended defensive actions

  • Assess exposure of FC United version 1.1.1 or earlier in your environment
  • Verify if any compensating controls are in place
  • Prioritize remediation or mitigation efforts for this vulnerability
  • Monitor for potential exploitation attempts

Evidence notes

The vulnerability was reported by Patchstack and is tracked under CVE-2026-66565. The NVD entry is currently in the 'Received' status.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-66565 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-66565

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-66565 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66565

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.