CVE-2026-27429CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Jun 17, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.Referenceshttps://patchstack.com/database/wordpress/theme/nifty/vulnerability/wordpress-nifty-theme-1-4-1-php-object-injection-vulnerability?_s_id=cve