Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Object Injection leading to Remote Code Execution through deserialization of untrusted data
Action: Patch Now
AI Analysis

Impact

The Gutentype theme processes serialized data supplied by users without proper validation, allowing attackers to inject malicious PHP objects. When the application deserializes this data, the injected objects can execute arbitrary methods, potentially giving the attacker full control over the site. This flaw may enable attackers to alter site content, inject scripts, or compromise the server’s filesystem if the code execution path is triggered.

Affected Systems

WordPress users running the ThemeREX Group Gutentype theme version 2.1.12 or earlier are affected. The vulnerability is present from the earliest released version up to and including 2.1.12. All installations that have not applied a newer version are at risk.

Risk and Exploitability

The flaw carries a CVSS score of 9.8, indicating a severe vulnerability. EPSS data is not available, making it unclear how frequently exploit attempts occur, but the lack of a KEV listing does not diminish the potential impact. Based on the description, the likely attack vector is remote via crafted HTTP requests that carry the malicious serialized payload. Successful exploitation would enable the attacker to execute server‑side code with whatever permissions the web application possesses.

Generated by OpenCVE AI on October 10, 2026 at 08:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Gutentype to a version newer than 2.1.12 to eliminate the insecure deserialization logic
  • If an upgrade is not immediately possible, disable or remove any functionality that accepts serialized input, such as custom data fields or settings that may be manipulated by users
  • Apply a WordPress security plugin that enforces strict input validation and monitors for unexpected object serialization to reduce the risk of exploitation while a fix is applied

Generated by OpenCVE AI on October 10, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
Title WordPress Gutentype theme <= 2.1.12 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:38.957Z

Reserved: 2026-07-13T06:14:38.874Z

Link: CVE-2026-62046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:04.777

Modified: 2026-10-10T08:17:04.777

Link: CVE-2026-62046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data