Junglewise Threat Intelligence

CVE-2026-39445: PressLayouts Alukas PHP Object Injection

CVE-2026-39445 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: PressLayouts.

Executive brief

The Alukas theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This theme is used to design and manage the appearance of WordPress websites. If exploited, an attacker could potentially take control of the website, access sensitive data, or disrupt services, especially if other vulnerable components are present on the server.

Technical details

The Alukas theme for WordPress contains a PHP Object Injection vulnerability in versions prior to 3.0.0 due to improper deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. While the attack complexity is rated as high, successful exploitation could lead to remote code execution, SQL injection, or full system compromise if a suitable Property-Oriented Programming (POP) chain is available within the environment. The vulnerability is resolved in version 3.0.0.

Affected products

  • PressLayouts Alukas < 3.0.0

Timeline

  • 2026-02-12: other: Reported by Phat RiO
  • 2026-04-22: disclosed: Vulnerability disclosed by Patchstack
  • 2026-06-17: advisory: NVD published CVE-2026-39445

References