SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-62105

CRITICAL · CVSS 9.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated PHP Object Injection in ThemeREX Addons versions prior to 2.45.0, potentially enabling attackers to execute arbitrary code on affected systems. This critical flaw poses a significant risk to any web applications utilizing these addons, particularly those that handle sensitive data or are publicly accessible. Organizations using ThemeREX Addons should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-62105
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%

Original NVD Description

Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.