PatchSiren

Mikado-Themes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40759

CVE-2026-40759 is a high-severity vulnerability in the Esmée theme, affecting versions up to 1.4. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 8.1, indicating a high level of severity. The CVE was published on 2026-06-17 and last modified on 2026-06-17. Users of the Esmée theme should take [truncated]

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40751

CVE-2026-40751 is a high-severity vulnerability in the Ashtanga WordPress theme, versions <= 1.2. This vulnerability allows unauthenticated PHP object injection, which can lead to serious security breaches. The CVSS score for this vulnerability is 8.1, indicating a high level of severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Ashtanga theme shoul [truncated]

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40739

CVE-2026-40739 is a high-severity vulnerability (CVSS Score: 8.1) affecting LuxeDrive theme versions <= 1.4. This vulnerability allows unauthenticated PHP object injection, which could potentially lead to code execution. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate the risk. The CVE record [cve-org [truncated]