Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution via PHP Object Injection
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a deserialization of untrusted data that allows an attacker to inject malicious objects into the PHP runtime. The flaw could enable the attacker to execute arbitrary code or manipulate the application state, resulting in full compromise of the affected WordPress site. The impact is high, reflected in a CVSS score of 9.8, and the weakness is categorized as CWE-502.

Affected Systems

The affected product is the WordPress Rosalinda theme developed by ThemeREX Group. Versions up through 1.2.4 (inclusive) are vulnerable; the vulnerability does not apply to releases newer than 1.2.4.

Risk and Exploitability

The absence of an EPSS score and lack of listing in the CISA KEV catalog do not diminish the risk, as the CVSS score indicates a severe flaw that can be exploited with moderate effort. The likely attack vector involves supplying crafted serialized input to the theme’s processing routines, which will accept and unserialize the data without proper validation. An attacker who can influence this input – for example, via a form, URL parameter, or embedded content – can trigger the injection and potentially execute code with the permissions of the WordPress instance.

Generated by OpenCVE AI on October 10, 2026 at 08:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Rosalinda theme to a version newer than 1.2.4; verify the new release removes the unsafe unserialize logic.
  • If an upgrade cannot be performed immediately, disable the Rosalinda theme and switch to a neutral or custom theme to halt the execution of vulnerable code.
  • Review the theme’s source for any remaining unserialize calls and remove or sanitize them, ensuring that all data processed by the theme comes from trusted sources.

Generated by OpenCVE AI on October 10, 2026 at 08:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.
Title WordPress Rosalinda theme <= 1.2.4 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:35.938Z

Reserved: 2026-09-19T00:23:25.964Z

Link: CVE-2026-93933

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:05.680

Modified: 2026-10-10T08:17:05.680

Link: CVE-2026-93933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:45:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data