Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Hygia theme for WordPress (ThemeREX Group) contains a deserialization of untrusted data flaw that enables PHP object injection. This weakness allows an attacker to craft a serialized payload that, when processed by the theme, can instantiate arbitrary PHP objects and execute arbitrary code. The CVSS score of 9.8 reflects the severity of this remote code execution potential and the significant impact on confidentiality, integrity, and availability of the affected site.

Affected Systems

WordPress sites using the ThemeREX Group Hygia theme, versions up to and including 1.21.0.

Risk and Exploitability

The CVSS score of 9.8 indicates an extremely high severity. The EPSS score is not available, but the absence of a listing in the CISA KEV catalog does not reduce the risk; the flaw is exploitation‑ready as it does not require privileged access or special conditions. Based on the description, it is inferred that an attacker can trigger the vulnerability by submitting a crafted serialized payload through a request that the theme processes, potentially from any user with access to the vulnerable input channel.

Generated by OpenCVE AI on October 10, 2026 at 08:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Hygia theme to the latest version (≥ 1.21.1).
  • Restrict any administrative or REST endpoints that accept serialized data used by the Hygia theme to trusted users only.
  • Continuously monitor site logs for unexpected deserialization activity and enforce strict input validation.

Generated by OpenCVE AI on October 10, 2026 at 08:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
Title WordPress Hygia theme <= 1.21.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:37.101Z

Reserved: 2026-09-19T00:23:25.965Z

Link: CVE-2026-93937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:06.187

Modified: 2026-10-10T08:17:06.187

Link: CVE-2026-93937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:45:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data