Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Greeny WordPress theme contains a PHP Object Injection vulnerability caused by the deserialization of untrusted data. This flaw permits malicious actors to craft serialized payloads that, when processed by the theme, can lead to the execution of arbitrary PHP code on the hosting server. The resulting impact is the potential acquisition of full control over the WordPress installation, compromising confidentiality, integrity and availability.

Affected Systems

This vulnerability affects ThemeREX Group's Greeny theme, specifically all releases up to and including version 2.10.0. Any WordPress site that has the Greeny theme installed and is running one of those versions is potentially susceptible to exploitation.

Risk and Exploitability

The flaw carries a CVSS score of 9.8, indicating a critical severity. The EPSS score is not available, so the historical exploitation frequency is unknown. The vulnerability is not listed in the CISA KEV catalog, but based on the description it is inferred that an attacker can trigger the flaw by sending malicious serialized data to the theme, potentially via a crafted HTTP request that includes the payload. This inference is not explicitly confirmed by the CVE data. The risk remains high for any exposed site with the vulnerable theme active.

Generated by OpenCVE AI on October 10, 2026 at 09:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Greeny theme to the latest patched version that removes the unsafe deserialization process.
  • If an upgrade cannot be performed immediately, deactivate or uninstall the Greeny theme to prevent the vulnerable code from executing.
  • If the theme must remain active, restrict access to any theme endpoints that perform deserialization to trusted administrators only, and sanitize all incoming data before it is deserialized.

Generated by OpenCVE AI on October 10, 2026 at 09:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
Title WordPress Greeny theme <= 2.10.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:37.570Z

Reserved: 2026-09-19T00:23:25.965Z

Link: CVE-2026-93940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:06.433

Modified: 2026-10-10T08:17:06.433

Link: CVE-2026-93940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:15:14Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data