MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 19 h ago, last 19 h ago, peak #5

Critical unauthenticated PHP object injection flaw found in Kalles theme

Original: ๐Ÿšจ EUVD-2026-96488 ๐Ÿ“Š Score: 9.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Kalles ๐Ÿข Vendor: The4 ๐Ÿ“… Updated: 2026-10-10 ๐Ÿ“ Unauthenticated P

A critical vulnerability, tracked as EUVD-2026-96488, has been published for Kalles, an e-commerce theme by vendor The4. The flaw is described as an unauthenticated PHP object injection, meaning attackers would not need credentials to exploit it. It carries a CVSS v3.1 severity score of 9.8 out of 10, placing it in the critical range. The advisory was updated on 10 October 2026, and site operators using Kalles are being urged to check for patches.

Why now: Security communities are highlighting the advisory because a maximum-severity, remotely exploitable flaw in a widely used e-commerce theme poses immediate risk to online stores.

KallesThe4ENISAEUVD-2026-96488

Open on mastodon โ†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1777492