CVE-2026-39551

WordPress Töbel theme <= 1.8.1 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.


We have discovered 138 live websites that are affected by CVE-2026-39551.

Run a Free Instant Scan




Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Jun 2, 2026
  • Updated - Jun 2, 2026

Credits

  • Denver Jackson | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-39551
United States16 websites



Italy29 websites
Spain8 websites
Germany8 websites
France7 websites
India6 websites
Portugal6 websites
Turkey5 websites
GB4 websites
Malaysia4 websites

Website Distribution by TLD

Number of websites using CVE-2026-39551
.com54 websites
.it26 websites
.de4 websites
.es4 websites
.be2 websites
.co.uk2 websites
.se2 websites
.eu2 websites
.pl2 websites
.at1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-39551

Top websites that are affected by CVE-2026-39551. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States***,***
***********.com Cyprus*,***,***
*********************.**.uk GB*,***,***
************.es Spain*,***,***
************.it France*,***,***
*************.it France*,***,***
**********************.com United States*,***,***
*********.in India*,***,***
*******.com Italy*,***,***
*******.com United States*,***,***
See full domain list