CVE-2026-32511: WordPress Stål theme < 1.7 - Arbitrary Object Instantiation vulnerability
Published Mar 25, 2026
·Updated
Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects Stål: from n/a through < 1.7.
Affected Software
1 affected component
Mikado-Themes Stal<1.7
Event History
Mar 25, 2026
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-32511?
CVE-2026-32511 is considered a critical vulnerability due to its potential for arbitrary object instantiation and object injection.
2
How do I fix CVE-2026-32511?
To fix CVE-2026-32511, update the Stål theme to version 1.7 or later immediately.
3
What software is affected by CVE-2026-32511?
CVE-2026-32511 affects the Mikado-Themes Stål theme versions earlier than 1.7.
4
What type of vulnerability is CVE-2026-32511?
CVE-2026-32511 is classified as an Arbitrary Object Instantiation vulnerability resulting from deserialization of untrusted data.
5
Can CVE-2026-32511 be exploited remotely?
Yes, CVE-2026-32511 can potentially be exploited remotely by an attacker to gain unauthorized access.