← Terug naar overzicht

A PHP Object Injection vulnerability has been identified in the FreightCo WordPress theme affecting versions 1.1.15 and earlier. The vulnerability is unauthenticated, meaning attackers do not need any credentials to exploit it. PHP Object Injection flaws can allow attackers to perform various malicious actions depending on available PHP classes in the application, potentially including remote code execution, file manipulation, or privilege escalation. The vulnerability is tracked as CVE-2026-66650 and has been documented by both the NVD and Patchstack. Users of the FreightCo WordPress theme are advised to update to a patched version immediately. The issue highlights ongoing risks associated with insecure deserialization in WordPress themes and plugins.

Affected products

  • FreightCo WordPress Theme <= 1.1.15

Related CVE's

  • CVE-2026-66650

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities