CVE-2026-27438: WordPress Kingler theme <= 1.7 - PHP Object Injection vulnerability
Published Mar 5, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through <= 1.7.
Affected Software
1 affected component
ThemeREX Kingler<=1.7
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates the vulnerability is remotely exploitable over the network, requires no privileges, no user interaction, and has low attack complexity.
2
What impact could successful exploitation have?
The CVSS vector rates confidentiality, integrity, and availability impact as high. Successful exploitation could therefore expose data, alter data, or disrupt service.
3
Which Kingler versions are affected?
The issue affects ThemeREX Kingler versions through and including 1.7. The earliest affected version is not specified.