CVE-2026-62105
massUnauthenticated PHP Object Injection in ThemeREX Addons WordPress Plugin
CVE-2026-62105 is an unauthenticated PHP object injection flaw (CWE-502, deserialization of untrusted data) in the ThemeREX Addons plugin for WordPress, affecting all versions below 2.45.0. Because the vulnerable deserialization path is reachable over the network without authentication, privileges, or user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N), any remote attacker can send a crafted serialized PHP payload to trigger it. Successful object injection can leverage PHP object chains in WordPress for high-impact outcomes such as arbitrary code execution, database manipulation, or file operations (CVSS 3.1 C:H/I:H/A:H), potentially leading to full site compromise. WordPress sites running ThemeREX Addons prior to 2.45.0 are affected, including sites where the plugin was installed automatically as a companion to a ThemeREX commercial theme rather than chosen by the site owner. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Update ThemeREX Addons to version 2.45.0 or later, checking the plugin list even on sites where it was installed automatically with a bundled ThemeREX theme. If immediate patching is not possible, apply WAF rules that restrict unauthenticated requests to the plugin's endpoints and review logs for unexpected admin users, modified files, or unusual serialized input. No public PoC or known exploitation is currently reported, but treat this critical (9.8) issue as a priority patch.
| ThemeREX Addons (WordPress plugin) | All versions below 2.45.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.