PatchSiren cyber security CVE debrief
CVE-2026-66565 axiomthemes CVE debrief
A critical vulnerability was found in the FC United WordPress theme, version 1.1.1 or earlier. This vulnerability allows unauthenticated PHP object injection, which could potentially lead to severe consequences.
- Vendor
- axiomthemes
- Product
- FC United
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders and security teams responsible for WordPress installations, particularly those using the FC United theme version 1.1.1 or earlier, should assess exposure and prioritize remediation efforts.
Why it matters
CVE-2026-66565 is a critical vulnerability in the FC United WordPress theme that allows unauthenticated PHP object injection. Defenders and security teams should assess exposure, prioritize remediation efforts, and verify compensating controls to mitigate potential consequences.
- Potential for severe consequences due to unauthenticated PHP object injection
- Requires verification of exposure and remediation efforts
- May impact WordPress installations using the FC United theme
Technical summary
The FC United WordPress theme, version 1.1.1 or earlier, is vulnerable to unauthenticated PHP object injection. This vulnerability is tracked under CVE-2026-66565 and has a critical CVSS score of 9.8.
Defensive priority
High priority should be given to assessing exposure and applying remediation, as the vulnerability has a critical CVSS score of 9.8.
Recommended defensive actions
- Assess exposure of FC United version 1.1.1 or earlier in your environment
- Verify if any compensating controls are in place
- Prioritize remediation or mitigation efforts for this vulnerability
- Monitor for potential exploitation attempts
Evidence notes
The vulnerability was reported by Patchstack and is tracked under CVE-2026-66565. The NVD entry is currently in the 'Received' status.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-66565 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-66565
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-66565 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66565
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.