ZeroHour

CVE-2026-62105

mass

Unauthenticated PHP Object Injection in ThemeREX Addons WordPress Plugin

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-62105 is an unauthenticated PHP object injection flaw (CWE-502, deserialization of untrusted data) in the ThemeREX Addons plugin for WordPress, affecting all versions below 2.45.0. Because the vulnerable deserialization path is reachable over the network without authentication, privileges, or user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N), any remote attacker can send a crafted serialized PHP payload to trigger it. Successful object injection can leverage PHP object chains in WordPress for high-impact outcomes such as arbitrary code execution, database manipulation, or file operations (CVSS 3.1 C:H/I:H/A:H), potentially leading to full site compromise. WordPress sites running ThemeREX Addons prior to 2.45.0 are affected, including sites where the plugin was installed automatically as a companion to a ThemeREX commercial theme rather than chosen by the site owner. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.

What to do: Update ThemeREX Addons to version 2.45.0 or later, checking the plugin list even on sites where it was installed automatically with a bundled ThemeREX theme. If immediate patching is not possible, apply WAF rules that restrict unauthenticated requests to the plugin's endpoints and review logs for unexpected admin users, modified files, or unusual serialized input. No public PoC or known exploitation is currently reported, but treat this critical (9.8) issue as a priority patch.

Affected
ThemeREX Addons (WordPress plugin)All versions below 2.45.0
Estimated exposure
mass≈200,000+ sites (plugin is reported in the order of 200,000 active installs) — ThemeREX Addons is a companion plugin bundled with many ThemeREX commercial themes and has historically shown roughly 200,000 active installations in the WordPress.org plugin directory, and most WordPress sites are internet-exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.