CVE-2026-22454: WordPress Solaris theme <= 2.5 - PHP Object Injection vulnerability
Published Mar 5, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2.5.
Affected Software
2 affected components
ThemeREX Solaris<=2.5
WordPress Solaris<=2.5
Event History
Mar 5, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated WordPress account or user interaction?
No. The CVSS vector indicates network-accessible exploitation with no privileges required and no user interaction required.
2
What could a successful attack allow?
The CVSS rating indicates high impact to confidentiality, integrity, and availability. Exploitation is rated critical with a 9.8 CVSS score.