A PHP Object Injection vulnerability has been identified in the FreightCo WordPress theme affecting versions 1.1.15 and earlier. The vulnerability is unauthenticated, meaning attackers do not need any credentials to exploit it. PHP Object Injection flaws can allow attackers to perform various malicious actions depending on available PHP classes in the application, potentially including remote code execution, file manipulation, or privilege escalation. The vulnerability is tracked as CVE-2026-66650 and has been documented by both the NVD and Patchstack. Users of the FreightCo WordPress theme are advised to update to a patched version immediately. The issue highlights ongoing risks associated with insecure deserialization in WordPress themes and plugins.