CVE-2026-65571: WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability
Published Aug 6, 2026
·Updated
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
Affected Software
1 affected component
WordPress 69 Clothing theme<=1.2.11.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress 69 Clothing themeto a version that resolves this vulnerability.Fixed in 1.2.11.1
Event History
Aug 6, 2026
CVE Published
via MITRE·02:27 PM
Data Sourced
via MITRE·02:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65571?
The severity of CVE-2026-65571 is critical with a score of 9.8.
2
How does CVE-2026-65571 affect the WordPress 69 Clothing theme?
CVE-2026-65571 allows unauthenticated PHP Object Injection in versions of the theme <= 1.2.11.1.
3
What are the potential impacts of CVE-2026-65571?
The potential impacts of CVE-2026-65571 include complete control over the affected WordPress site, leading to data theft or site defacement.
4
How do I fix CVE-2026-65571?
To fix CVE-2026-65571, update the WordPress 69 Clothing theme to a version higher than 1.2.11.1.
5
Is CVE-2026-65571 exploitable remotely?
Yes, CVE-2026-65571 is exploitable remotely as it does not require authentication for execution.