Junglewise Threat Intelligence

CVE-2026-39576: Elated-Themes SingleMalt PHP Object Injection

CVE-2026-39576 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Elated-Themes.

Executive brief

SingleMalt, a theme for WordPress websites, contains a security flaw that allows unauthorized users to inject malicious code. If exploited, an attacker could potentially take full control of the website, steal sensitive data, or disrupt services. This vulnerability is particularly dangerous because it does not require a login to exploit.

Technical details

A PHP Object Injection vulnerability exists in the SingleMalt theme for WordPress (versions <= 1.5) due to improper deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to arbitrary code execution, SQL injection, or file system traversal. The vulnerability is mitigated in version 1.6.

Affected products

  • Elated-Themes SingleMalt <= 1.5

Timeline

  • 2026-02-12: other: Reported by Denver Jackson
  • 2026-04-08: disclosed: Vulnerability details published by Patchstack
  • 2026-06-17: advisory: CVE published to NVD

References