CVE-2026-66564CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Oct 10, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.Referenceshttps://patchstack.com/database/wordpress/theme/shift-cv/vulnerability/wordpress-shiftcv-theme-3-0-14-php-object-injection-vulnerability?_s_id=cve