CVE-2026-27084: WordPress Buisson theme <= 1.1.11 - PHP Object Injection vulnerability
Published Mar 25, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11.
Affected Software
1 affected component
ThemeREX Buisson (WordPress theme)<=1.1.11
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27084?
CVE-2026-27084 has a critical severity rating due to its potential for PHP Object Injection, allowing attackers to execute arbitrary code.
2
How do I fix CVE-2026-27084?
To fix CVE-2026-27084, upgrade the ThemeREX Buisson theme to version 1.1.12 or later immediately.
3
What versions of the Buisson theme are affected by CVE-2026-27084?
CVE-2026-27084 affects ThemeREX Buisson theme versions up to and including 1.1.11.
4
What kind of vulnerabilities does CVE-2026-27084 represent?
CVE-2026-27084 represents a PHP Object Injection vulnerability which is exploited through the deserialization of untrusted data.
5
What are the potential consequences of exploiting CVE-2026-27084?
Exploitation of CVE-2026-27084 could allow attackers to manage arbitrary code execution, potentially compromising the entire server.