CVE-2026-62045: WordPress Booklovers theme <= 2.13.0 - PHP Object Injection vulnerability
Published Oct 10, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
Affected Software
1 affected component
ThemeREX Group Booklovers<=2.13.0
Event History
Oct 10, 2026
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The reported vector is network-accessible and requires no privileges or user interaction. The available data therefore indicates that an unauthenticated remote attacker could exploit it if a vulnerable installation exposes the affected functionality.
2
Which Booklovers versions are affected?
Booklovers versions through 2.13.0 are affected. The lower bound is listed as unspecified.
3
What is the potential impact?
The vulnerability is rated critical with a CVSS score of 9.8 and is assessed as having high confidentiality, integrity, and availability impact. It involves deserialization of untrusted data leading to PHP object injection.