Junglewise Threat Intelligence

CVE-2026-40761: Edge-Themes Valeska PHP Object Injection

CVE-2026-40761 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Edge-Themes.

Executive brief

Valeska is a WordPress theme used for website design and layout. A security flaw in versions 1.2.2 and earlier allows an unauthenticated attacker to inject malicious code into the website. If exploited, this could lead to full site takeover, data theft, or the site being used to spread malware, potentially damaging the organization's reputation and digital operations.

Technical details

A PHP Object Injection vulnerability exists in the Valeska theme for WordPress (versions <= 1.2.2) due to improper deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to a vulnerable component of the theme. If a suitable Property-Oriented Programming (POP) chain is present in the environment, the attacker could achieve remote code execution, perform SQL injection, or access sensitive files. The vulnerability is mitigated in version 1.3.

Affected products

  • Edge-Themes Valeska <= 1.2.2

Timeline

  • 2026-02-24: other: Reported by Denver Jackson
  • 2026-04-20: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References