PatchSiren

Mikado-Themes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Mikado-Themes CVE published 2026-07-13

CVE-2026-57792

CVE-2026-57792 is a HIGH severity vulnerability in D? by Mikado-Themes. The issue is an Improper Control of Filename for Include/Require Statement in PHP Program, allowing for PHP Local File Inclusion. This vulnerability affects D? from n/a through version 2.4.1. Users of D? by Mikado-Themes, version 2.4.1 or earlier, should apply patches or mitigations. The CVSS score is 7.5, and it is classified as HIGH severity.

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-52707

CVE-2026-52707 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Kastell theme, affecting versions <= 2.0. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T14:17:57.053Z and last modified on 2026-06-17T15:17:00.290Z. Users of Kastell theme versions <= 2.0 should take immediate action to mitigate this vulnerability.

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40757

The Château theme, version 1.2.1 or earlier, is vulnerable to an unauthenticated PHP object injection attack. This HIGH-severity vulnerability, with a CVSS score of 8.1, could allow attackers to execute arbitrary code on affected systems. Users of the Château theme should update to the latest version immediately. This vulnerability was made public on June 17, 2026. The vulnerability is tracked under CVE-2026-40757.

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40756

CVE-2026-40756 is a high-severity vulnerability in the Zoya theme, affecting versions <= 1.4. This vulnerability allows unauthenticated PHP object injection, which can lead to significant damage. The CVSS score is 8.1, indicating a high level of severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Zoya theme should take immediate action to mitigate th [truncated]

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40733

CVE-2026-40733 is a HIGH-severity vulnerability (CVSS Score: 8.1) affecting the ShiftUp theme, version <= 1.3. This Unauthenticated PHP Object Injection vulnerability allows attackers to inject malicious PHP objects without authentication. Successful exploitation could lead to code execution, data breaches, or system compromise. The vulnerability was published on 2026-06-17. Users of affected versions sho [truncated]

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40759

CVE-2026-40759 is a high-severity vulnerability in the Esmée theme, affecting versions up to 1.4. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 8.1, indicating a high level of severity. The CVE was published on 2026-06-17 and last modified on 2026-06-17. Users of the Esmée theme should take [truncated]

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40755

CVE-2026-40755 is a high-severity vulnerability in TechLink, a WordPress theme developed by Mikado-Themes. The vulnerability is an unauthenticated PHP object injection, which can lead to potential code execution. The CVSS score for this vulnerability is 8.1, indicating a high level of severity. The vulnerability affects TechLink versions up to and including 1.3.

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40753

CVE-2026-40753 is an Unauthenticated PHP Object Injection vulnerability in the EasyMeals theme versions <= 1.5.1. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. This type of vulnerability allows attackers to execute arbitrary PHP code, potentially leading to significant impact on affected systems. Users of EasyMeals theme version 1.5.1 or earlier should apply patches or miti [truncated]

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40751

CVE-2026-40751 is a high-severity vulnerability in the Ashtanga WordPress theme, versions <= 1.2. This vulnerability allows unauthenticated PHP object injection, which can lead to serious security breaches. The CVSS score for this vulnerability is 8.1, indicating a high level of severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Ashtanga theme shoul [truncated]

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40739

CVE-2026-40739 is a high-severity vulnerability (CVSS Score: 8.1) affecting LuxeDrive theme versions <= 1.4. This vulnerability allows unauthenticated PHP object injection, which could potentially lead to code execution. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate the risk. The CVE record [cve-org [truncated]

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-40731

CVE-2026-40731 is a high-severity vulnerability in ChapterOne theme versions <= 1.7, allowing unauthenticated local file inclusion. The vulnerability has a CVSS score of 8.1 and is considered HIGH. The CVE record was published on 2026-06-17T13:20:35.700Z and was last modified on 2026-06-17T15:16:49.890Z. This vulnerability may allow attackers to access sensitive files, potentially leading to information d [truncated]

HIGH Mikado-Themes CVE published 2026-06-17

CVE-2026-39537

CVE-2026-39537 is an unauthenticated local file inclusion vulnerability in Mikado Core versions <= 1.6. The vulnerability has a CVSS score of 8.1 and is rated HIGH. The CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Users of Mikado Core versions <= 1.6 should prioritize patching this vulnerability to prevent potential exploitation. The vulnerability's operational impact is likely significant [truncated]

HIGH Mikado-Themes CVE published 2026-04-08

CVE-2026-39538

A high-severity vulnerability, CVE-2026-39538, was found in Mikado Core, a WordPress plugin. This PHP Local File Inclusion vulnerability has a CVSS score of 7.5 and could allow attackers to include local files, potentially leading to code execution. The vulnerability affects Mikado Core versions from n/a through 1.6. Users of Mikado Core, especially those with versions up to 1.6, should be aware of this v [truncated]