Junglewise Threat Intelligence

CVE-2026-40751: Mikado-Themes Ashtanga PHP object injection

CVE-2026-40751 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Mikado-Themes.

Executive brief

The Ashtanga theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This could lead to a complete takeover of the website, theft of customer data, or a total service outage. Site owners should update to version 1.3 immediately to prevent potential mass-exploitation campaigns.

Technical details

A PHP Object Injection vulnerability exists in the Ashtanga theme for WordPress (versions <= 1.2) due to the improper deserialization of untrusted data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present on the server, this can lead to arbitrary code execution, SQL injection, or file system traversal. The vulnerability is addressed in version 1.3.

Affected products

  • Mikado-Themes Ashtanga <= 1.2

Timeline

  • 2026-02-24: other: Reported by Denver Jackson
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD

References