Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-65574: WordPress Abogado Theme <= 1.18 Exposes Data to Attackers
CVE-2026-65574
CVE-2026-65574
Summary
If you're using the Abogado theme in WordPress, versions 1.18 and older are vulnerable to a security threat. This means an attacker could potentially access sensitive data without needing a password. To stay safe, update to the latest version of the Abogado theme.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ancorathemes | abogado | <= 1.18 |
Original title
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
Original description
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
nvd CVSS3.1
9.8
Vulnerability type
CWE-502
Deserialization of Untrusted Data
Published: 6 Aug 2026 · Updated: 7 Aug 2026 · First seen: 6 Aug 2026