CVE-2026-39529CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Jun 17, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.Referenceshttps://patchstack.com/database/wordpress/theme/elementra/vulnerability/wordpress-elementra-theme-1-0-9-php-object-injection-vulnerability?_s_id=cve