Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a deserialization of untrusted data flaw in the Travesia WordPress theme, allowing an attacker to inject a malicious PHP object. An attacker who can supply crafted serialized input can trigger arbitrary code execution within the theme context, potentially compromising site data and the underlying server. The flaw is classified as insecure deserialization and is rated CVSS 9.8, indicating a critical risk.

Affected Systems

ThemeREX Group’s Travesia theme, from its initial release through version 1.1.16, is affected. Any WordPress site deploying any version of Travesia up to and including 1.1.16 remains vulnerable until the theme is upgraded past this point.

Risk and Exploitability

The CVSS base score of 9.8 reflects that the vulnerability can be exploited without authentication and with an attacker‑controlled input. Although no EPSS value is provided, the high severity and lack of mitigation in the current theme suggest a high likelihood of exploitation if the vulnerability is public. The vulnerability is not listed in the CISA KEV catalogue, but the attack vector is inferred to be through any user‑supplied serialized data handled by the theme, likely via HTTP requests or form submissions. No additional prerequisites are noted in the provided description.

Generated by OpenCVE AI on October 10, 2026 at 08:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Travesia theme to the latest available version (≥ 1.1.17) that contains the patch for insecure deserialization.
  • If an immediate upgrade is not feasible, temporarily deactivate the Travesia theme or replace it with a non‑vulnerable alternative to eliminate the vulnerable code path.
  • For sites that must continue running the vulnerable theme, restrict all inputs that are deserialized by the theme to trusted, validated data, and remove or sanitize any serialized payloads, ideally by disabling or explicitly blocking the use of PHP’s unserialize function for untrusted data.

Generated by OpenCVE AI on October 10, 2026 at 08:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16.
Title WordPress Travesia theme <= 1.1.16 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:34.898Z

Reserved: 2026-09-19T00:23:25.964Z

Link: CVE-2026-93929

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:05.183

Modified: 2026-10-10T08:17:05.183

Link: CVE-2026-93929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:45:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data