Unauthenticated PHP Object Injection in ThemeREX Addons by ThemeREX
CVE-2026-62105
9.8CRITICAL
What is CVE-2026-62105?
An unauthenticated PHP Object Injection vulnerability exists in ThemeREX Addons versions prior to 2.45.0. This flaw allows attackers to exploit the PHP object injection, potentially leading to code execution or compromising the security of affected systems. Website administrators using outdated versions of this plugin should prioritize updates to mitigate the risk of exploitation.
Affected Version(s)
ThemeREX Addons < 2.45.0