These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-57792 is a HIGH severity vulnerability in D? by Mikado-Themes. The issue is an Improper Control of Filename for Include/Require Statement in PHP Program, allowing for PHP Local File Inclusion. This vulnerability affects D? from n/a through version 2.4.1. Users of D? by Mikado-Themes, version 2.4.1 or earlier, should apply patches or mitigations. The CVSS score is 7.5, and it is classified as HIGH severity.
CVE-2026-52707 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Kastell theme, affecting versions <= 2.0. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T14:17:57.053Z and last modified on 2026-06-17T15:17:00.290Z. Users of Kastell theme versions <= 2.0 should take immediate action to mitigate this vulnerability.
The Château theme, version 1.2.1 or earlier, is vulnerable to an unauthenticated PHP object injection attack. This HIGH-severity vulnerability, with a CVSS score of 8.1, could allow attackers to execute arbitrary code on affected systems. Users of the Château theme should update to the latest version immediately. This vulnerability was made public on June 17, 2026. The vulnerability is tracked under CVE-2026-40757.
CVE-2026-40756 is a high-severity vulnerability in the Zoya theme, affecting versions <= 1.4. This vulnerability allows unauthenticated PHP object injection, which can lead to significant damage. The CVSS score is 8.1, indicating a high level of severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Zoya theme should take immediate action to mitigate th [truncated]
CVE-2026-40733 is a HIGH-severity vulnerability (CVSS Score: 8.1) affecting the ShiftUp theme, version <= 1.3. This Unauthenticated PHP Object Injection vulnerability allows attackers to inject malicious PHP objects without authentication. Successful exploitation could lead to code execution, data breaches, or system compromise. The vulnerability was published on 2026-06-17. Users of affected versions sho [truncated]
CVE-2026-40759 is a high-severity vulnerability in the Esmée theme, affecting versions up to 1.4. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 8.1, indicating a high level of severity. The CVE was published on 2026-06-17 and last modified on 2026-06-17. Users of the Esmée theme should take [truncated]
CVE-2026-40755 is a high-severity vulnerability in TechLink, a WordPress theme developed by Mikado-Themes. The vulnerability is an unauthenticated PHP object injection, which can lead to potential code execution. The CVSS score for this vulnerability is 8.1, indicating a high level of severity. The vulnerability affects TechLink versions up to and including 1.3.
CVE-2026-40753 is an Unauthenticated PHP Object Injection vulnerability in the EasyMeals theme versions <= 1.5.1. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. This type of vulnerability allows attackers to execute arbitrary PHP code, potentially leading to significant impact on affected systems. Users of EasyMeals theme version 1.5.1 or earlier should apply patches or miti [truncated]
CVE-2026-40751 is a high-severity vulnerability in the Ashtanga WordPress theme, versions <= 1.2. This vulnerability allows unauthenticated PHP object injection, which can lead to serious security breaches. The CVSS score for this vulnerability is 8.1, indicating a high level of severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Ashtanga theme shoul [truncated]
CVE-2026-40739 is a high-severity vulnerability (CVSS Score: 8.1) affecting LuxeDrive theme versions <= 1.4. This vulnerability allows unauthenticated PHP object injection, which could potentially lead to code execution. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate the risk. The CVE record [cve-org [truncated]
CVE-2026-40731 is a high-severity vulnerability in ChapterOne theme versions <= 1.7, allowing unauthenticated local file inclusion. The vulnerability has a CVSS score of 8.1 and is considered HIGH. The CVE record was published on 2026-06-17T13:20:35.700Z and was last modified on 2026-06-17T15:16:49.890Z. This vulnerability may allow attackers to access sensitive files, potentially leading to information d [truncated]
CVE-2026-39537 is an unauthenticated local file inclusion vulnerability in Mikado Core versions <= 1.6. The vulnerability has a CVSS score of 8.1 and is rated HIGH. The CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Users of Mikado Core versions <= 1.6 should prioritize patching this vulnerability to prevent potential exploitation. The vulnerability's operational impact is likely significant [truncated]
A high-severity vulnerability, CVE-2026-39538, was found in Mikado Core, a WordPress plugin. This PHP Local File Inclusion vulnerability has a CVSS score of 7.5 and could allow attackers to include local files, potentially leading to code execution. The vulnerability affects Mikado Core versions from n/a through 1.6. Users of Mikado Core, especially those with versions up to 1.6, should be aware of this v [truncated]