Junglewise Threat Intelligence

CVE-2026-40760: Edge-Themes Behold PHP Object Injection

CVE-2026-40760 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Edge-Themes.

Executive brief

The Behold theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This theme is used to customize the appearance and layout of WordPress websites. If exploited, an attacker could potentially take control of the website, steal sensitive data, or disrupt services, even without having a login account.

Technical details

A PHP Object Injection vulnerability exists in the Edge-Themes Behold theme for WordPress in versions up to and including 1.5. The flaw is rooted in the deserialization of untrusted data (CWE-502), allowing an unauthenticated remote attacker to inject PHP objects. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to various high-impact attacks including remote code execution, SQL injection, or arbitrary file deletion. The vulnerability is mitigated in version 1.6.

Affected products

  • Edge-Themes Behold <= 1.5

Timeline

  • 2026-02-24: other: Vulnerability reported by Denver Jackson
  • 2026-04-20: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References