CVE-2026-62105
9.8ThemeRex · ThemeREX Addons
ThemeREX Addons for WordPress is affected by an unauthenticated PHP object injection vulnerability, allowing remote code execution via deserialization of untrusted data.
Executive summary
A critical unauthenticated PHP object injection vulnerability in the ThemeREX Addons plugin for WordPress poses a severe risk of complete system compromise.
Vulnerability
This vulnerability involves the deserialization of untrusted data (CWE-502), which allows an unauthenticated attacker to inject malicious PHP objects. By targeting the plugin, an attacker can achieve remote code execution, effectively gaining full control over the affected WordPress instance.
Business impact
The CVSS score of 9.8 reflects the high risk associated with this vulnerability, as it allows for unauthenticated remote code execution. A successful exploit could lead to complete data exfiltration, unauthorized modification of site content, and potential lateral movement into the hosting environment. Organizations relying on this plugin face significant reputational and operational risks due to the potential for total system takeover.
Remediation
Immediate Action: Update the ThemeREX Addons plugin to version 2.45.0 or later immediately to resolve the deserialization flaw.
Proactive Monitoring: Review web server access logs for anomalous requests containing serialized PHP objects or unexpected POST requests to the plugin endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious serialized object strings or malicious input patterns directed at WordPress plugins.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS severity and the ease of exploitation for unauthenticated attackers, immediate patching is required. Administrators should prioritize updating the ThemeREX Addons plugin across all environments, as this vulnerability provides a direct pathway for full system compromise.
More ThemeRex CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by nh4tvd | Patchstack Bug Bounty Program, per the CVE Program record.