CVE-2026-66672CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Aug 20, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Flatastic <= 2.0 versions.Referenceshttps://patchstack.com/database/wordpress/theme/flatastic/vulnerability/wordpress-flatastic-theme-2-0-php-object-injection-vulnerability?_s_id=cve