Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-65574: WordPress Abogado Theme <= 1.18 Exposes Data to Attackers

CVE-2026-65574 CVE-2026-65574
Summary

If you're using the Abogado theme in WordPress, versions 1.18 and older are vulnerable to a security threat. This means an attacker could potentially access sensitive data without needing a password. To stay safe, update to the latest version of the Abogado theme.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ancorathemes abogado <= 1.18
Original title
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
Original description
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
nvd CVSS3.1 9.8
Vulnerability type
CWE-502 Deserialization of Untrusted Data
Published: 6 Aug 2026 · Updated: 7 Aug 2026 · First seen: 6 Aug 2026