CVE-2026-66650: WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Affected Software
1 affected component
FreightCo WordPress theme<=1.1.15
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation.
2
What versions are affected?
FreightCo theme versions 1.1.15 and earlier are identified as affected.
3
What is the potential impact?
The supplied severity vector indicates network-reachable exploitation with low attack complexity and no user interaction, with high potential impact to confidentiality, integrity, and availability.