Junglewise Threat Intelligence

CVE-2026-62105: ThemeREX Addons PHP object injection

CVE-2026-62105 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Vendors: ThemeREX.

Executive brief

ThemeREX Addons is a popular WordPress plugin providing theme customization and extension features. A PHP object injection flaw in versions before 2.45.0 allows unauthenticated attackers to execute arbitrary code on affected websites, potentially leading to full server compromise, data theft, and malware installation.

Technical details

The vulnerability is a PHP object injection flaw (CWE-502, Deserialization of Untrusted Data) in ThemeREX Addons plugin versions below 2.45.0. The flaw permits unauthenticated attackers to inject malicious PHP objects that are unsafely deserialized, enabling arbitrary code execution on the server. No authentication or user interaction is required; the attack is network-accessible. Successful exploitation allows an attacker to execute arbitrary PHP code with the privileges of the web server process, potentially leading to complete site takeover. The vulnerability was patched in version 2.45.0 and should be applied immediately.

Affected products

  • ThemeREX Addons < 2.45.0

Timeline

  • 2026-09-11: disclosed: Vulnerability published on NVD and Patchstack
  • 2026-09-11: patched: Fix available in version 2.45.0

References