CVE-2026-93937: WordPress Hygia theme <= 1.21.0 - PHP Object Injection vulnerability
Published Oct 10, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
Affected Software
1 affected component
ThemeREX Group Hygia<=1.21.0
Event History
Oct 10, 2026
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Hygia theme versions through 1.21.0 are affected. The available data does not identify a fixed version or any configuration prerequisites.
2
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates network-accessible exploitation with low attack complexity, no privileges required, and no user interaction required.
3
What impact could successful exploitation have?
The vulnerability is rated critical with a 9.8 CVSS score and is assessed as having high confidentiality, integrity, and availability impact.