Unauthenticated PHP Object Injection in ThemeREX Addons by ThemeREX
CVE-2026-62105

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 September 2026

What is CVE-2026-62105?

An unauthenticated PHP Object Injection vulnerability exists in ThemeREX Addons versions prior to 2.45.0. This flaw allows attackers to exploit the PHP object injection, potentially leading to code execution or compromising the security of affected systems. Website administrators using outdated versions of this plugin should prioritize updates to mitigate the risk of exploitation.

Affected Version(s)

ThemeREX Addons < 2.45.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nh4tvd | Patchstack Bug Bounty Program
.