CVE-2026-66569CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Oct 10, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.Referenceshttps://patchstack.com/database/wordpress/theme/kicker/vulnerability/wordpress-kicker-theme-2-2-1-php-object-injection-vulnerability?_s_id=cve