Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-93927: Veto theme up to 1.6 lets attackers run code
CVE-2026-93927 · published today
Summary
The Veto theme for WordPress (versions through 1.6.0) can be tricked into processing specially crafted data, which may let a malicious person execute code on your site. This could lead to unauthorized actions, data loss, or site takeover. Update the theme to a newer version or replace it with a secure alternative as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| axiomthemes | veto | <= 1.6.0 |
Original advisory text
WordPress Veto theme <= 1.6.0 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically (estimated)
- Gives an attacker full control (estimated)
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published10 Oct 2026
Updated10 Oct 2026
First seen10 Oct 2026
Track software like this
Free during beta