CVE-2026-28105: WordPress Good Energy theme <= 1.7.7 - PHP Object Injection vulnerability
Published Mar 5, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a through <= 1.7.7.
Affected Software
2 affected components
ThemeREX Good Energy<=1.7.7
WordPress Good Energy<=1.7.7
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28105?
CVE-2026-28105 is considered a high severity vulnerability due to its potential for PHP Object Injection via deserialization of untrusted data.
2
How do I fix CVE-2026-28105?
To mitigate CVE-2026-28105, upgrade the Good Energy theme to version 1.7.8 or later immediately.
3
What versions of Good Energy are affected by CVE-2026-28105?
CVE-2026-28105 affects all versions of the Good Energy theme from its release up to and including version 1.7.7.
4
What is the impact of CVE-2026-28105?
Exploiting CVE-2026-28105 allows attackers to perform PHP Object Injection, which could lead to arbitrary code execution on the affected website.
5
Who is the vendor for the vulnerable software associated with CVE-2026-28105?
The vendor for the affected software associated with CVE-2026-28105 is ThemeREX.