CVE-2026-27082: WordPress Love Story theme <= 1.3.12 - PHP Object Injection vulnerability
Published Mar 25, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.
Affected Software
1 affected component
ThemeREX Love Story (WordPress theme)<=1.3.12
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27082?
CVE-2026-27082 is classified as a critical severity vulnerability due to its potential for PHP Object Injection leading to remote code execution.
2
How do I fix CVE-2026-27082?
To fix CVE-2026-27082, update the ThemeREX Love Story theme to version 1.3.13 or later.
3
What software is affected by CVE-2026-27082?
CVE-2026-27082 affects the ThemeREX Love Story WordPress theme versions up to and including 1.3.12.
4
What type of vulnerability is CVE-2026-27082?
CVE-2026-27082 is a PHP Object Injection vulnerability caused by deserialization of untrusted data.
5
Who is the vendor for CVE-2026-27082?
The vendor for CVE-2026-27082 is ThemeREX, the developer of the Love Story WordPress theme.