
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40759 is an unauthenticated PHP Object Injection vulnerability affecting the Esmée WordPress theme (by Mikado-Themes) in versions 1.4 and below. The vulnerability was published on June 17, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High), reflecting network-accessible exploitation with no authentication or user interaction required, though with high attack complexity (Feedly, ENISA EUVD).
The root cause is improper deserialization of untrusted data (CWE-502), classified under CAPEC-586 (Object Injection). An unauthenticated remote attacker can supply a crafted serialized PHP object to a vulnerable endpoint in the Esmée theme, which is then deserialized without adequate validation. Depending on the PHP classes available in the application's scope (gadget chains), this can lead to arbitrary code execution, file manipulation, or other malicious outcomes (Feedly, Patchstack).
Successful exploitation can result in full compromise of the affected WordPress installation, including arbitrary code execution, unauthorized reading of sensitive data (e.g., credentials, configuration files), modification of application data, and potential denial of service. Because the attack requires no authentication, any internet-exposed WordPress site running the Esmée theme ≤ 1.4 is at risk, and a successful compromise could serve as a foothold for lateral movement within the hosting environment (Feedly).
/wp-content/themes/esme/), or tools like WPScan.O:, a:, s: typical of PHP serialization)./wp-content/uploads/ or theme directories); unexpected changes to wp-config.php or .htaccess.bash, curl, wget, python) that are not typical for normal WordPress operation.The primary remediation is to upgrade the Esmée theme to a version greater than 1.4 (version 1.5 or later), which addresses the vulnerability. As interim mitigations, administrators should implement a web application firewall (WAF) rule to block requests containing PHP serialized object patterns targeting theme endpoints, apply network-level access controls to restrict exposure of the WordPress admin and theme endpoints, and monitor application logs for suspicious deserialization activity. Input validation and sanitization of all user-supplied data before deserialization should be enforced at the application level (Feedly, Patchstack).
The vulnerability was reported and assigned by Patchstack, a WordPress security specialist. Wordfence referenced the vulnerability in their weekly WordPress vulnerability report for the week of April 20–26, 2026. No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been identified (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."