These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-57793 is a high-severity vulnerability in the Flow theme, allowing PHP Remote File Inclusion. The issue affects Flow from n/a through version 1.8. Users of the Flow theme, particularly those with unpatched versions, should be aware of this vulnerability. The vulnerability is caused by improper control of filename for include/require statements in PHP programs, also known as PHP Remote File Inclus [truncated]
CVE-2026-39576 is a high-severity vulnerability (CVSS Score: 8.1) affecting the SingleMalt theme, versions <= 1.5. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to code execution, data breaches, or system compromise. The vulnerability was published on June 17, 2026, and immediately gained attention due to its high severity and potential impact. Users of the [truncated]
CVE-2026-39556 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Konsept theme, affecting versions up to 1.9. This Unauthenticated PHP Object Injection vulnerability allows attackers to inject malicious PHP objects without authentication, potentially leading to code execution, data breaches, or system compromise. The vulnerability was published on June 17, 2026, and immediately gained attention du [truncated]
CVE-2026-39523 is an Unauthenticated Local File Inclusion vulnerability in Solene Core versions <= 2.3.2. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. Affected product deployments should be identified and owners assigned for follow-up. Official advisories and CVE records should be reviewed to validate affected scope, severity, and vendor guidance.
CVE-2026-40758 is a high-severity vulnerability in the Léonie theme, affecting versions up to 1.2.1. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to arbitrary code execution. The CVSS score for this vulnerability is 8.1, indicating a high level of severity. Organizations using the affected Léonie theme versions should take immediate action to mitigate this [truncated]
CVE-2026-40754 is a high-severity vulnerability in the Roisin WordPress theme, affecting versions up to 1.4. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to code execution. With a CVSS score of 8.1, this issue is considered High severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should [truncated]
CVE-2026-39578 is a medium-severity vulnerability in the Valiance theme, affecting versions <= 1.2. This vulnerability allows unauthenticated PHP object injection, which could potentially lead to security issues. The CVSS score for this vulnerability is 5.5. The vulnerability was published on June 17, 2026, at 13:20:21 UTC and modified at 14:44:26 UTC on the same day. Users of the Valiance theme should ta [truncated]
CVE-2026-39577 is a medium-severity vulnerability in the Playroom theme, affecting versions up to 1.4.1. The vulnerability allows unauthenticated PHP object injection, which could potentially lead to security issues. The CVSS score for this vulnerability is 5.5, indicating a medium level of severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Playroom [truncated]
CVE-2026-39568 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Mr. SEO theme for WordPress versions <= 2.0. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T13:20:20.703Z and last modified on 2026-06-17T14:44:26.397Z. Users of affected versions should take immediate action to mitigate potential risks.
CVE-2026-39558 is an Unauthenticated Local File Inclusion vulnerability in Malmö theme versions <= 2.2. This vulnerability has a high CVSS score of 8.1, indicating a high severity. Users of Malmö theme version <= 2.2 should be aware of this vulnerability and take necessary actions to mitigate it. The vulnerability allows attackers to include local files without authentication, potentially leading to sensi [truncated]
CVE-2026-39557 is a high-severity vulnerability in the NeoBeat theme for WordPress, with a CVSS score of 8.1. It allows unauthenticated PHP object injection, potentially leading to code execution. This type of vulnerability can be particularly dangerous as it may allow attackers to execute arbitrary PHP code on vulnerable installations, potentially leading to full control of the affected system. The vulne [truncated]
CVE-2026-39554 is a high-severity vulnerability in the Fidalgo WordPress theme, affecting versions up to 1.2.2. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to code execution, data breaches, or system compromise. With a CVSS score of 8.1, this issue demands immediate attention. The vulnerability was published on June 17, 2026, and last modified on the same [truncated]
CVE-2026-39549 is a HIGH severity vulnerability (CVSS score: 8.1) affecting Aperitif theme versions <= 1.5. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T13:20:20.043Z and last modified on 2026-06-17T14:44:26.397Z. Users of Aperitif theme versions <= 1.5 should take immediate action to mitigate this vulnerability. The vulnerability is tracked by Patchs [truncated]
CVE-2026-39522 is an Unauthenticated Local File Inclusion vulnerability in Solene theme versions <= 3.4. The CVSS score is 8.1, indicating HIGH severity. The CVE record was published on 2026-06-17T13:20:18.597Z and was last modified on 2026-06-17T14:44:26.397Z. This type of vulnerability allows attackers to include local files on the server, potentially leading to code execution or sensitive information d [truncated]