CVE-2026-93940: WordPress Greeny theme <= 2.10.0 - PHP Object Injection vulnerability
Published Oct 10, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
Affected Software
1 affected component
ThemeREX Group Greeny<=2.10.0
Event History
Oct 10, 2026
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Greeny theme versions through 2.10.0 are affected. The available data does not identify a fixed version.
2
Can this be exploited remotely without authentication?
The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required. It also indicates potential high impact to confidentiality, integrity, and availability.