Summary
CVE-2026-65576 is an unauthenticated PHP Object Injection vulnerability in the Adrena WordPress theme by AncoraThemes, affecting all versions up to and including 1.2.14. The flaw stems from deserialization of untrusted data (CWE-502) and carries a CVSS v3.1 base score of 9.8 (Critical), allowing complete compromise of an affected site.
Technical details
- Root cause: Unsafe deserialization of untrusted, attacker-controlled data (CWE-502), allowing injection of malicious PHP objects.
- Trigger conditions: No authentication is required; the vulnerability is reachable by an unauthenticated actor.
- Attack vector: Network (remotely exploitable), low attack complexity, no privileges and no user interaction required.
- Impact: High impact to confidentiality, integrity, and availability; when a suitable POP gadget chain is present, PHP Object Injection can lead to full site compromise.
Affected software
- Adrena WordPress Theme (AncoraThemes) — versions up to and including 1.2.14.
Severity
- CVSS v3.1 base score: 9.8 (Critical)
- Vector string:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No fixed version is listed in the public advisory at time of writing. Monitor AncoraThemes and the WordPress theme repository for an update newer than 1.2.14 and apply it as soon as it is released.
- If no patch: Restrict or virtually patch the affected theme at the network/WAF layer, consider disabling or removing the Adrena theme until a fixed release is available, and limit exposure of the affected site to untrusted networks.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw HTTP response body:
/wp-content/themes/adrena/

