PatchSiren

Edge-Themes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Edge-Themes CVE published 2026-07-13

CVE-2026-57800

CVE-2026-57800 is a PHP Remote File Inclusion vulnerability in the Overworld theme, affecting versions from n/a through <= 1.5. This issue allows attackers to perform PHP Local File Inclusion attacks. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. Users of the Overworld theme, especially those with version 1.5 or earlier, should apply patches or mitigations to prevent potential attacks. [truncated]

HIGH Edge-Themes CVE published 2026-07-13

CVE-2026-57788

CVE-2026-57788 is a PHP Local File Inclusion vulnerability in Edge-Themes Aalto aalto, affecting versions from n/a through <= 1.8. The vulnerability is caused by Improper Control of Filename for Include/Require Statement in PHP Program, also known as PHP Remote File Inclusion. Users of Edge-Themes Aalto aalto plugin for WordPress should be aware of this HIGH severity vulnerability rated at 7.5 CVSS score. [truncated]

HIGH Edge-Themes CVE published 2026-06-17

CVE-2026-40738

CVE-2026-40738 is a high-severity vulnerability in the Eldon theme, versions <= 1.4.1, allowing unauthenticated PHP object injection. This vulnerability has a CVSS score of 8.1 and is considered HIGH severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Eldon theme should take immediate action to mitigate this vulnerability. The vulnerability is caused [truncated]

HIGH Edge-Themes CVE published 2026-06-17

CVE-2026-40761

CVE-2026-40761 is a high-severity vulnerability in the Valeska theme, affecting versions up to 1.2.2. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to arbitrary code execution. The CVSS score for this vulnerability is 8.1, indicating a high level of severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the V [truncated]

HIGH Edge-Themes CVE published 2026-06-17

CVE-2026-40760

CVE-2026-40760 is an Unauthenticated PHP Object Injection vulnerability in the Behold theme, affecting versions up to and including 1.5. The vulnerability has a CVSS score of 8.1, indicating high severity. It was published on 2026-06-17 and last modified on 2026-06-17. The vulnerability could allow an attacker to execute arbitrary PHP code, potentially leading to unauthorized access, data breaches, or oth [truncated]

HIGH Edge-Themes CVE published 2026-06-17

CVE-2026-40735

CVE-2026-40735 is a high-severity vulnerability in Reina theme versions <= 2.1, allowing unauthenticated PHP object injection. This vulnerability has a CVSS score of 8.1 and is considered HIGH severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of Reina theme versions <= 2.1 are advised to take immediate action to mitigate this vulnerability. The vulnerabil [truncated]

HIGH Edge-Themes CVE published 2026-06-17

CVE-2026-39539

CVE-2026-39539 is a high-severity vulnerability in the Alloggio - Hotel Booking WordPress theme, versions up to 2.1.2. The vulnerability allows unauthenticated PHP object injection, which can lead to arbitrary code execution. This vulnerability has a CVSS score of 8.1 and is considered HIGH severity. The vulnerability was published on June 17, 2026, and last modified on the same day.