Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from unsafe deserialization of data supplied by users, allowing an attacker to instantiate arbitrary PHP objects within the Hogwords WordPress theme; this flaw can lead to remote code execution on the affected site and is classified as CWE-502, deserialization of untrusted data.

Affected Systems

ThemeREX Group's Hogwords theme, versions 1.2.7 and earlier, are affected. Any installation of Hogwords up to and including 1.2.7 is vulnerable, regardless of minor patch releases. Versions newer than 1.2.7 are presumed not to contain the flaw.

Risk and Exploitability

With a CVSS score of 9.8, this issue is considered extremely severe. No EPSS data is available, and the vulnerability is not currently listed in the CISA KEV catalogue. Attackers would need to supply malicious serialized data that is processed by the theme; the vector is most likely through web requests accepted by the theme, such as form submissions or cookie data. This defect can be exploited by anyone who can influence the data that the theme deserializes, potentially allowing arbitrary code execution on the server.

Generated by OpenCVE AI on October 10, 2026 at 08:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Hogwords theme to a version newer than 1.2.7.
  • If an upgrade is not immediately possible, restrict or remove any functionality that accepts serialized data and enforce strict validation or sanitization on user inputs.
  • Review the theme code for unsafe unserialize calls and replace them with secure deserialization functions or disable the affected feature until a patch is released.

Generated by OpenCVE AI on October 10, 2026 at 08:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
Title WordPress Hogwords theme <= 1.2.7 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:37.342Z

Reserved: 2026-09-19T00:23:25.965Z

Link: CVE-2026-93938

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:06.310

Modified: 2026-10-10T08:17:06.310

Link: CVE-2026-93938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:45:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data