Junglewise Threat Intelligence

CVE-2026-40756: Mikado-Themes Zoya PHP Object Injection

CVE-2026-40756 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Mikado-Themes.

Executive brief

The Zoya theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This could lead to a complete takeover of the website, theft of customer data, or disruption of services. Business owners using this theme should update to version 1.5 immediately to prevent potential automated attacks.

Technical details

The Zoya theme for WordPress (versions <= 1.4) is vulnerable to PHP Object Injection via the deserialization of untrusted data (CWE-502). An unauthenticated remote attacker can exploit this vulnerability by submitting specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker could achieve remote code execution, perform SQL injection, or conduct path traversal. The vulnerability is addressed in version 1.5.

Affected products

  • Mikado-Themes Zoya <= 1.4

Timeline

  • 2026-02-24: other: Vulnerability reported by Denver Jackson
  • 2026-04-20: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: CVE published and NVD record created

References