Junglewise Threat Intelligence

CVE-2026-40739: Mikado-Themes LuxeDrive PHP object injection

CVE-2026-40739 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Mikado-Themes.

Executive brief

LuxeDrive is a WordPress theme used for building professional websites. A security flaw allows an unauthenticated attacker to inject malicious code into the website's server. If successfully exploited, this could lead to a total takeover of the website, theft of customer data, or a complete service outage.

Technical details

A PHP Object Injection vulnerability exists in the LuxeDrive theme for WordPress (versions <= 1.4) due to the insecure deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker can achieve remote code execution, SQL injection, or arbitrary file access. The vulnerability is mitigated in version 1.5.

Affected products

  • Mikado-Themes LuxeDrive <= 1.4

Timeline

  • 2026-02-12: other: Vulnerability reported by Denver Jackson
  • 2026-04-16: advisory: Patchstack published advisory details
  • 2026-06-17: disclosed: CVE published to NVD

References