🔐 CVE Alert

CVE-2026-23544

HIGH 8.8

WordPress Valenti theme <= 5.6.3.5 - PHP Object Injection vulnerability

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.

CWE CWE-502
Vendor codetipi
Product valenti
Published Feb 19, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for codetipi valenti

Be the first to know when new high vulnerabilities affecting codetipi valenti are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

codetipi / Valenti
0 ≤ 5.6.3.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Theme/valenti/vulnerability/wordpress-valenti-theme-5-6-3-5-php-object-injection-vulnerability?_s_id=cve

Credits

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program