CVE-2026-78529CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Oct 10, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Alliance <= 3.11 versions.Referenceshttps://patchstack.com/database/wordpress/theme/alliance/vulnerability/wordpress-alliance-theme-3-11-php-object-injection-vulnerability?_s_id=cve