PatchSiren

Select-Themes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Select-Themes CVE published 2026-07-13

CVE-2026-57805

CVE-2026-57805 is a HIGH severity vulnerability in Tonda theme, a PHP Local File Inclusion vulnerability. The CVE record was published on 2026-07-13T10:16:44.807Z and has not been modified since then. The vulnerability allows attackers to include local files via a manipulated filename, potentially leading to unauthorized access or code execution. Users of Tonda theme should be aware of this vulnerability [truncated]

HIGH Select-Themes CVE published 2026-07-13

CVE-2026-57803

CVE-2026-57803 is a HIGH severity vulnerability (CVSS Score: 7.5) in the Struktur Core plugin, allowing for PHP Local File Inclusion due to improper control of filenames for include/require statements. The vulnerability affects Struktur Core from n/a through version 2.5.1. Users of Struktur Core plugin version 2.5.1 or earlier should apply patches or mitigations to prevent potential PHP Local File Inclusi [truncated]

HIGH Select-Themes CVE published 2026-07-13

CVE-2026-57802

CVE-2026-57802 is a PHP Remote File Inclusion vulnerability in Struktur theme, allowing PHP Local File Inclusion. The issue affects Struktur from n/a through <= 2.5.1. This HIGH severity vulnerability has a CVSS score of 7.5. Users of Struktur theme version 2.5.1 or earlier should assess and mitigate this vulnerability. The CVE record was published on 2026-07-13T10:16:44.453Z and has not been modified since then.

HIGH Select-Themes CVE published 2026-07-13

CVE-2026-57801

A vulnerability was found in the SetSail theme for WordPress, affecting versions up to and including 2.1. This issue allows for PHP Local File Inclusion due to improper control of filenames for include/require statements, categorized as a PHP Remote File Inclusion vulnerability. The vulnerability's CVSS score is 7.5, indicating a high severity level. Users and administrators of WordPress installations usi [truncated]

HIGH Select-Themes CVE published 2026-06-17

CVE-2026-40752

CVE-2026-40752 is a HIGH-severity vulnerability (CVSS Score: 8.1) affecting Manufaktur Solutions theme versions <= 1.1.1. This vulnerability allows unauthenticated PHP Object Injection, potentially leading to code execution, data breaches, or system compromise. The vulnerability was published on June 17, 2026, and immediately gained attention due to its high severity and potential impact. Users of the aff [truncated]

HIGH Select-Themes CVE published 2026-06-17

CVE-2026-39560

CVE-2026-39560 is a high-severity vulnerability in the Hiroshi theme, affecting versions up to 1.5.1. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to code execution and unauthorized access. The CVSS score for this vulnerability is 8.1, indicating a high level of severity. Organizations using the affected versions of the Hiroshi theme should take immediate [truncated]

HIGH Select-Themes CVE published 2026-06-17

CVE-2026-39580

CVE-2026-39580 is a high-severity vulnerability in the Micdrop theme for WordPress, affecting versions up to and including 1.3.1. The vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to code execution, data breaches, or other malicious activities. With a CVSS score of 8.1, this vulnerability is considered high-risk and requires immediate attention. Administrators o [truncated]

HIGH Select-Themes CVE published 2026-06-17

CVE-2026-39573

CVE-2026-39573 is a high-severity vulnerability in the Mildhill theme, allowing unauthenticated PHP object injection. The vulnerability has a CVSS score of 8.1 and was published on June 17, 2026. The affected version is 1.5 or earlier. Users of the Mildhill theme should take immediate action to mitigate this vulnerability. The vulnerability allows attackers to inject malicious PHP objects, potentially lea [truncated]

HIGH Select-Themes CVE published 2026-06-17

CVE-2026-39567

CVE-2026-39567 is a high-severity vulnerability in the Santé theme for WordPress, allowing unauthenticated PHP object injection. This vulnerability has a CVSS score of 8.1 and was published on 2026-06-17. The affected versions are <= 1.5.1. Users of the Santé theme should take immediate action to mitigate this vulnerability. The vulnerability was reported by Patchstack and is tracked by CVE.org and NVD. N [truncated]

HIGH Select-Themes CVE published 2026-06-17

CVE-2026-39547

CVE-2026-39547 is an Unauthenticated Local File Inclusion vulnerability in the Getaway theme for WordPress versions before 1.8. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. It allows unauthenticated attackers to include local files, potentially leading to code execution, data exposure, or other malicious activities.

HIGH Select-Themes CVE published 2026-06-17

CVE-2026-39545

CVE-2026-39545 is a high-severity vulnerability in the Zermatt theme, affecting versions up to 1.6.1. The vulnerability allows for unauthenticated PHP object injection, which can lead to significant impacts including high confidentiality, integrity, and availability risks. The CVSS score for this vulnerability is 8.1, indicating a high level of severity. Users of the Zermatt theme should take immediate ac [truncated]