CVE-2026-66482: WordPress Drone Media theme <= 2.2.0 - PHP Object Injection vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated PHP Object Injection in Drone Media <= 2.2.0 versions.
Affected Software
1 affected component
WordPress Drone Media<=2.2.0
Event History
Oct 10, 2026
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation.
2
What is the potential impact if exploitation succeeds?
The supplied severity vector indicates high impact to confidentiality, integrity, and availability. The vulnerability is remotely exploitable with low attack complexity and requires no user interaction.
3
Which installations are affected?
WordPress sites using the Drone Media theme version 2.2.0 or earlier are identified as affected.