← Terug naar overzicht

A PHP Object Injection vulnerability has been identified in the FreightCo WordPress theme affecting versions 1.1.15 and below. The vulnerability is unauthenticated, meaning attackers do not need any credentials to exploit it. PHP Object Injection vulnerabilities can allow attackers to perform various attacks depending on available PHP classes, potentially including remote code execution, file manipulation, or other malicious actions. The vulnerability has been assigned CVE-2026-66650 and is documented on both the NVD and Patchstack databases. Users of the FreightCo theme are advised to update to a patched version beyond 1.1.15 to mitigate this risk. The unauthenticated nature of this vulnerability raises its severity, as it widens the attack surface to any external threat actor without requiring prior access.

Affected products

  • FreightCo WordPress Theme <= 1.1.15

Related CVE's

  • CVE-2026-66650

Categories

  • Web Technologies