Junglewise Threat Intelligence

CVE-2026-39567: Select-Themes Santé PHP Object Injection

CVE-2026-39567 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Select-Themes.

Executive brief

The Santé theme for WordPress is vulnerable to a security flaw that allows unauthorized attackers to inject malicious code into a website. This theme is used to manage the visual layout and functionality of WordPress sites. If exploited, an attacker could potentially take full control of the website, steal sensitive customer data, or cause a total service outage.

Technical details

A PHP Object Injection vulnerability exists in the Santé theme for WordPress (versions <= 1.5.1) due to improper deserialization of untrusted data (CWE-502). An unauthenticated remote attacker can exploit this by submitting specially crafted input to a vulnerable component. If a suitable Property-Oriented Programming (POP) chain is present on the server, the attacker can achieve remote code execution, perform SQL injection, or conduct path traversal. The vulnerability is mitigated in version 1.6. Although the attack vector is network-based and requires no privileges, the CVSS complexity is rated as high, likely due to the requirement of a valid POP chain for full exploitation.

Affected products

  • Select-Themes Santé <= 1.5.1

Timeline

  • 2026-02-12: other: Reported by Denver Jackson
  • 2026-04-08: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD

References