CVE-2026-62076CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Oct 10, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Kalles <= 1.1.7.1 versions.Referenceshttps://patchstack.com/database/wordpress/theme/kalles/vulnerability/wordpress-kalles-theme-1-1-7-1-php-object-injection-vulnerability?_s_id=cve