CVE-2026-27439: WordPress Dentario theme <= 1.5 - PHP Object Injection vulnerability
Published Mar 5, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <= 1.5.
Affected Software
1 affected component
ThemeREX Dentario<=1.5
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27439?
CVE-2026-27439 has a severity rating of medium due to its potential for PHP Object Injection affecting WordPress Dentario theme.
2
How do I fix CVE-2026-27439?
To fix CVE-2026-27439, update the WordPress Dentario theme to a version above 1.5 that addresses the vulnerability.
3
What type of vulnerability is CVE-2026-27439?
CVE-2026-27439 is classified as a PHP Object Injection vulnerability involving deserialization of untrusted data.
4
Which versions of the Dentario theme are affected by CVE-2026-27439?
CVE-2026-27439 affects the ThemeREX Dentario theme versions from n/a up to and including version 1.5.
5
What can an attacker achieve with CVE-2026-27439?
An attacker exploiting CVE-2026-27439 may gain the ability to execute arbitrary PHP code on the affected WordPress site.