CVE-2026-39554HIGH NVDCVSS Score 8.1Severity HIGHPublished Jun 17, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.Referenceshttps://patchstack.com/database/wordpress/theme/fidalgo/vulnerability/wordpress-fidalgo-theme-1-2-2-php-object-injection-vulnerability?_s_id=cve