CVE-2026-65578CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Aug 06, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Agora <= 1.9 versions.Referenceshttps://patchstack.com/database/wordpress/theme/agora/vulnerability/wordpress-agora-theme-1-9-php-object-injection-vulnerability?_s_id=cve