Junglewise Threat Intelligence

CVE-2026-39539: Edge-Themes Alloggio PHP Object Injection

CVE-2026-39539 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Edge-Themes.

Executive brief

Alloggio is a WordPress theme used by hotels and hospitality businesses to manage bookings and reservations. A security flaw allows unauthenticated attackers to inject malicious data into the system, which could lead to full website takeover, data theft, or service disruption. This vulnerability is particularly dangerous because it does not require a login to exploit.

Technical details

The Alloggio - Hotel Booking theme for WordPress is vulnerable to PHP Object Injection in versions up to and including 2.1.2. This issue stems from the deserialization of untrusted data (CWE-502) provided by a user without proper validation. An unauthenticated remote attacker can exploit this by submitting specially crafted input to a vulnerable component. If a suitable Property-Oriented Programming (POP) chain is present on the server, the attacker could achieve remote code execution, perform SQL injection, or conduct path traversal. The vulnerability is resolved in version 2.1.3.

Affected products

  • Edge-Themes Alloggio - Hotel Booking <= 2.1.2

Timeline

  • 2026-02-11: other: Vulnerability reported by Denver Jackson
  • 2026-04-08: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: CVE published to NVD
  • 2026-04-08: patched: Version 2.1.3 released to address the issue

References