Junglewise Threat Intelligence

CVE-2026-39550: Elated-Themes Aperitif PHP object injection

CVE-2026-39550 · Severity: high · CVSS 8.1 · Published 2026-06-02

Vendors: Elated-Themes.

Executive brief

Aperitif, a professional WordPress theme by Elated-Themes, contains a security flaw that could allow an attacker to take control of a website. By sending specially crafted data to the site, an unauthorized user could potentially execute malicious code, steal sensitive information, or disrupt the website's operations. This vulnerability is considered high priority because it can be exploited remotely without needing any login credentials.

Technical details

A PHP Object Injection vulnerability exists in the Elated-Themes Aperitif theme for WordPress due to the insecure deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by submitting malicious input that is processed by the PHP unserialize() function. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker could achieve remote code execution, perform SQL injection, or cause a denial of service. The vulnerability affects versions up to and including 1.6 and has been addressed in version 1.6.1.

Affected products

  • Elated-Themes Aperitif <= 1.6

Timeline

  • 2026-02-12: other: Reported by Denver Jackson
  • 2026-04-08: advisory: Initial disclosure by Patchstack
  • 2026-06-02: disclosed: CVE published to NVD dataset

References

Related threats