CVE-2026-62105: WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ThemeREX Addons Pluginto a version that resolves this vulnerability.Fixed in 2.45.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
Which installations are affected?
WordPress sites using ThemeREX Addons versions earlier than 2.45.0 are affected. The provided data does not identify any configuration prerequisite or mitigation other than moving off affected versions.
What security impact could successful exploitation have?
The reported severity is critical, with high impacts to confidentiality, integrity, and availability. Successful exploitation could therefore expose data, enable unauthorized modification, and disrupt service.