CVE-2026-49108CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Jun 17, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Moderno < 1.43 versions.Referenceshttps://patchstack.com/database/wordpress/theme/moderno/vulnerability/wordpress-moderno-theme-1-43-php-object-injection-vulnerability?_s_id=cve