
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39560 is an unauthenticated PHP Object Injection vulnerability affecting the Hiroshi WordPress theme by Select-Themes in versions 1.5.1 and earlier. Disclosed on June 17, 2026, the vulnerability allows a remote, unauthenticated attacker to inject malicious PHP objects over the network, potentially leading to remote code execution. It carries a CVSS v3.1 base score of 8.1 (High), reflecting high complexity but no authentication requirement (GitHub Advisory).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), meaning the Hiroshi theme deserializes attacker-controlled input without adequate validation. An unauthenticated attacker can craft a malicious serialized PHP object and submit it to a vulnerable endpoint in the theme; if a suitable "gadget chain" exists within the WordPress installation or its plugins, this can be leveraged to execute arbitrary code. The attack vector is network-based with high complexity (AC:H), indicating that exploitation requires specific conditions or a gadget chain to be present (GitHub Advisory, Patchstack).
Successful exploitation can result in full compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. An attacker could execute arbitrary code, read or modify sensitive data, delete files, or establish persistent access to the web server. The scope is limited to the affected component, but lateral movement within the hosting environment is possible depending on server configuration (GitHub Advisory).
O: patterns in POST body or query parameters); unexpected outbound connections from the web server process.bash, curl, wget, python) not associated with normal WordPress operation.Site administrators should update the Hiroshi WordPress theme to a version greater than 1.5.1 as soon as a patched release is available from Select-Themes. Until a patch is applied, consider deactivating the Hiroshi theme and switching to an alternative, or using a web application firewall (WAF) rule to block requests containing serialized PHP object patterns to theme endpoints. Monitor the official Patchstack advisory and GitHub Advisory for patch availability and additional guidance (GitHub Advisory, Patchstack).
The vulnerability was reported by Patchstack, which assigned and disclosed the CVE on June 17, 2026. A brief mention was noted on Mastodon shortly after disclosure, but no significant broader media coverage or notable researcher commentary has been observed. Community reaction has been minimal, consistent with the low EPSS score and absence of public exploit code (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."