CVE-2026-39445HIGH NVDCVSS Score 8.1Severity HIGHPublished Jun 17, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Alukas < 3.0.0 versions.Referenceshttps://patchstack.com/database/wordpress/theme/alukas/vulnerability/wordpress-alukas-theme-3-0-0-php-object-injection-vulnerability?_s_id=cve