Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The IPharm WordPress theme contains a PHP deserialization flaw that allows untrusted data to be deserialized into objects. Exploitation of this flaw can lead to arbitrary code execution, compromising the integrity, confidentiality, and availability of the affected WordPress site. The vulnerability is classified as CWE-502, indicating a PHP Object Injection weakness.

Affected Systems

ThemeREX Group’s IPharm theme is affected for all releases up to and including version 1.2.4, and any build that has not applied the vendor’s patch beyond this version.

Risk and Exploitability

The CVSS score of 9.8 highlights severe risk, and no EPSS data is published, so the probability cannot be precisely quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves any endpoint that accepts user‑controlled input and passes it to PHP’s unserialize function. An attacker could manipulate serialized objects sent via form data, URLs, or other user‑supplied fields to override object properties or trigger destructive methods. Given the high impact and lack of immediate mitigation from the vendor, remediation should be considered urgent.

Generated by OpenCVE AI on October 10, 2026 at 09:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the IPharm theme to the latest version that contains the fix for the serialization vulnerability.
  • If an update is unavailable, deactivate the theme or switch to a trusted alternative until the vendor releases a patch.
  • Implement general WordPress hardening measures: disable file editing, remove unused plugins, restrict file permissions, and use a security plugin to monitor for malicious activity.

Generated by OpenCVE AI on October 10, 2026 at 09:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
Title WordPress IPharm theme <= 1.2.4 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:36.862Z

Reserved: 2026-09-19T00:23:25.965Z

Link: CVE-2026-93936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:06.060

Modified: 2026-10-10T08:17:06.060

Link: CVE-2026-93936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:15:14Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data