CVE-2026-93930: WordPress Tantra theme <= 2.9.0 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra allows Object Injection.This issue affects Tantra: from n/a through 2.9.0.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
The issue affects ThemeREX Group Tantra versions through 2.9.0. The available data does not identify a fixed version or any configuration conditions that would exclude an installation.
What does an attacker need to exploit this issue?
The CVSS vector indicates network exploitation with low attack complexity, no required privileges, and no user interaction. The vulnerability is an unsafe deserialization issue that can allow PHP object injection.
What is the potential impact?
The reported severity is critical, with high impact to confidentiality, integrity, and availability. Successful exploitation could therefore expose data, enable unauthorized modification, or disrupt affected sites.