Junglewise Threat Intelligence

CVE-2026-39443: PressLayouts EmallShop PHP object injection

CVE-2026-39443 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: PressLayouts.

Executive brief

EmallShop is a professional e-commerce theme for WordPress websites. A security vulnerability in versions 2.4.21 and earlier allows unauthenticated attackers to inject malicious objects into the site's processing logic. If exploited, this could lead to full site takeover, data theft, or the execution of unauthorized commands, potentially disrupting business operations and compromising customer information.

Technical details

The EmallShop theme for WordPress is vulnerable to PHP Object Injection in versions up to 2.4.21 due to the deserialization of untrusted data (CWE-502). An unauthenticated remote attacker can exploit this vulnerability by submitting specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present in the environment, the attacker could achieve remote code execution, perform SQL injection, or conduct path traversal. The vulnerability is addressed in version 2.4.22.

Affected products

  • PressLayouts EmallShop <= 2.4.21

Timeline

  • 2026-02-12: other: Vulnerability reported by researcher Phat RiO
  • 2026-04-22: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References