Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-62105: ThemeREX Addons allows remote code execution via object injection
CVE-2026-62105 · published 17 days ago
Summary
An attacker does not need login credentials to send specially crafted data to ThemeREX Addons versions before 2.45.0, causing the system to run unwanted code. This could let the attacker take control of the website or steal information. Upgrade the plugin to version 2.45.0 or later, or apply the vendor's recommended patch, to close the risk.
What to do
- Update themerex themerex addons to version 2.45.0.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| themerex | themerex addons |
< 2.45.0 Fix: upgrade to 2.45.0
|
Original advisory text
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published11 Sep 2026
Updated27 Sep 2026
First seen11 Sep 2026
Track software like this
Free during beta