CVE-2026-78535CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Oct 10, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.Referenceshttps://patchstack.com/database/wordpress/theme/photolia/vulnerability/wordpress-photolia-theme-1-0-3-php-object-injection-vulnerability?_s_id=cve