Junglewise Threat Intelligence

CVE-2026-40758: Elated-Themes Léonie PHP Object Injection

CVE-2026-40758 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Elated-Themes.

Executive brief

The Léonie theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This could lead to full website takeover, data theft, or the site being used to spread malware. Business operations may be disrupted if the site is defaced or taken offline by an attacker.

Technical details

A PHP Object Injection vulnerability exists in the Léonie theme for WordPress (versions <= 1.2.1) due to improper deserialization of untrusted data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to arbitrary code execution, SQL injection, or full system compromise. The vulnerability is addressed in version 1.3.

Affected products

  • Elated-Themes Léonie <= 1.2.1

Timeline

  • 2026-02-24: other: Reported by Denver Jackson
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date

References