Junglewise Threat Intelligence

CVE-2026-39545: Select-Themes Zermatt PHP Object Injection

CVE-2026-39545 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Select-Themes.

Executive brief

The Zermatt theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This could lead to a complete takeover of the website, theft of customer data, or a total service outage. Business owners should update the theme to version 1.7 immediately to prevent potential mass-exploitation attacks.

Technical details

A PHP Object Injection vulnerability exists in the Zermatt theme for WordPress (versions <= 1.6.1) due to improper deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present on the server, this can lead to remote code execution, SQL injection, or arbitrary file access. The vulnerability is mitigated in version 1.7.

Affected products

  • Select-Themes Zermatt <= 1.6.1

Timeline

  • 2026-02-11: other: Vulnerability reported by Denver Jackson
  • 2026-04-08: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: CVE published to NVD

References