CRITICAL 9.8 CVE-2026-78533 Published 10 Oct 2026

Qwery WordPress Theme PHP Object Injection Vulnerability

Worried this affects your website?

Qwery versions up to and including 3.6.1 are vulnerable to an unauthenticated PHP object injection flaw.

The vulnerability can be triggered without authentication, allowing attackers to inject serialized PHP objects.

Reference: CVE-2026-78533 on NVD

← Back to Security News