Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1839 articles · 106847 vulns · 38/55 feeds (7d)
← Back to list
—
CVE-2026-22505

WordPress Morning Records theme <= 1.2 - PHP Object Injection vulnerability

Description

Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection.This issue affects Morning Records: from n/a through <= 1.2.

Affected Products

VendorProductVersions
AncoraThemesMorning Recordsn/a

References

  • https://patchstack.com/database/Wordpress/Theme/morning-records/vulnerability/wordpress-morning-records-theme-1-2-php-object-injection-vulnerability?_s_id=cve(vdb-entry)

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-22505 | AncoraThemes Morning Records Plugin up to 1.2 on WordPress deserialization
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-502
Published3/25/2026
Last enriched1h agov2
Tags
CVE-2026-22505
Trending Score41
Source articles2
Independent1
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Version History

v2
Last enriched 1h ago
v2Tier C1h ago

Updated severity to CRITICAL, marked as actively exploited, and added CVE-2026-22505 as a tag.

severityactivelyExploitedtags
via VulDB
v12h ago

Initial creation