Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-42723: CleanSkin theme lets attackers run code on site

CVE-2026-42723 · published today
Summary

The CleanSkin theme for WordPress (versions up to 1.5.0) can be tricked into executing code without any login. This means a malicious visitor could take control of your website or steal data. Update the theme to a newer version or switch to a different, supported theme as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ancorathemes cleanskin <= 1.5.0
Original advisory text
WordPress CleanSkin theme <= 1.5.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in CleanSkin <= 1.5.0 versions.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.8 Critical
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published10 Oct 2026
Updated10 Oct 2026
First seen10 Oct 2026
Sources
CVE-2026-42723 · MITRE
Track software like this
Free during beta