CVE-2026-40754HIGH NVDCVSS Score 8.1Severity HIGHPublished Jun 17, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Roisin <= 1.4 versions.Referenceshttps://patchstack.com/database/wordpress/theme/roisin/vulnerability/wordpress-roisin-theme-1-4-php-object-injection-vulnerability?_s_id=cve