Junglewise Threat Intelligence

CVE-2026-40736: Edge-Themes Laurits PHP Object Injection

CVE-2026-40736 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Edge-Themes.

Executive brief

The Laurits theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This theme is used to design and manage the appearance of WordPress websites. If exploited, an attacker could potentially take full control of the website, steal sensitive data, or disrupt services, even without having a login account.

Technical details

The Laurits theme for WordPress (versions <= 1.5.1) contains a PHP Object Injection vulnerability due to improper deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by submitting specially crafted input to a vulnerable component of the theme. If a suitable Property-Oriented Programming (POP) chain is present on the server, this can lead to remote code execution, arbitrary file deletion, or unauthorized database access. The vulnerability is mitigated in version 1.6.

Affected products

  • Edge-Themes Laurits <= 1.5.1

Timeline

  • 2026-02-12: other: Reported by Denver Jackson
  • 2026-04-16: disclosed: Vulnerability published by Patchstack
  • 2026-06-17: advisory: CVE published to NVD

References