Junglewise Threat Intelligence

CVE-2026-39573: Select-Themes Mildhill PHP object injection

CVE-2026-39573 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Select-Themes.

Executive brief

The Mildhill theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code into a website. This could lead to complete site takeover, data theft, or service disruption. Website owners should update the theme to version 1.6 immediately to protect their operations and customer data.

Technical details

A PHP Object Injection vulnerability exists in the Mildhill WordPress theme (versions <= 1.5) due to the unsafe deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker could achieve remote code execution, perform SQL injection, or access sensitive files. The vulnerability is addressed in version 1.6.

Affected products

  • Select-Themes Mildhill <= 1.5

Timeline

  • 2026-02-12: other: Reported by Denver Jackson
  • 2026-04-08: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References