CVE-2026-39443HIGH NVDCVSS Score 8.1Severity HIGHPublished Jun 17, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.Referenceshttps://patchstack.com/database/wordpress/theme/emallshop/vulnerability/wordpress-emallshop-theme-2-4-21-php-object-injection-vulnerability?_s_id=cve