Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Deserialization of untrusted data in the WordPress Let's Play theme allows an attacker to inject malicious PHP objects. When an object is deserialized without proper validation, the theme can instantiate arbitrary classes, leading to execution of unintended code. This flaw is a classic PHP Object Injection, classified under CWE-502, and can compromise the confidentiality, integrity, and availability of the affected WordPress site.

Affected Systems

The vulnerability affects the Let's Play theme distributed by ThemeREX Group. All versions from the earliest release up to and including 1.1.15 are affected. WordPress sites that have this theme installed and are accessible via the web are at risk.

Risk and Exploitability

The CVSS base score of 9.8 indicates critical severity. The EPSS score is not available, but the lack of a listed KEV record suggests exploit activity is not yet widespread; however, the nature of PHP deserialization in a public website gives attackers ample opportunity. The likely attack vector is a remote web request that includes crafted serialized data, such as via POST parameters or query strings. Successful exploitation would allow the attacker to execute arbitrary code on the server, giving full control over the site and possibly the underlying server environment.

Generated by OpenCVE AI on October 10, 2026 at 09:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Let’s Play theme to a version newer than 1.1.15 where the deserialization issue is fixed.
  • If an update is not possible or immediately available, replace the theme with a secure alternative and delete all files from the vulnerable version.
  • Apply a web application firewall rule that filters or strips serialized PHP objects from incoming requests to block attempted object injection until a patch is applied.

Generated by OpenCVE AI on October 10, 2026 at 09:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
Title WordPress Let's Play theme <= 1.1.15 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:36.635Z

Reserved: 2026-09-19T00:23:25.965Z

Link: CVE-2026-93935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:05.933

Modified: 2026-10-10T08:17:05.933

Link: CVE-2026-93935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:15:14Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data