Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a deserialization of untrusted data, allowing PHP object injection in the Edema WordPress theme. This weakness is a classic example of CWE-502 and can enable attackers to execute arbitrary code or inject malicious objects that persist across requests. The potential impact is full compromise of the target website, including data theft, defacement, or further lateral movement within the hosting environment. The description does not specify the exact privileges gained, but given the nature of object injection, an attacker could likely elevate to any permissions the WordPress user running the theme possesses.

Affected Systems

Angular vendor ThemeREX Group’s Edema theme for WordPress is affected, with all releases from the initial public version up through 1.2.2.2 susceptible to the flaw. Versions prior to 1.2.2.2 and any releases beyond that point contain the remediation. Site owners running any of the vulnerable theme versions should identify their installation and verify the current version number.

Risk and Exploitability

The CVSS score of 9.8 indicates the flaw is considered Critical, and the vulnerability is not listed in the CISA KEV catalog, though the EPSS score is not available. Because the flaw occurs during deserialization of user‑controlled data, the likely attack vector is remote, with an attacker crafting a manipulated payload in a HTTP request that reaches the theme’s processing endpoint. Such an attack does not appear to require privileged access beyond normal web traffic, making it potentially exploitable by anyone who can access the site. The absence of an EPSS rating does not diminish the criticality implied by the CVSS score, and administrators should treat the vulnerability as a high‑risk exposure until resolved.

Generated by OpenCVE AI on October 10, 2026 at 08:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Edema theme to the latest version (1.2.2.3 or newer) that removes the untrusted deserialization logic.
  • If an update is not immediately possible, switch the website to a non‑vulnerable theme to eliminate the attack surface.
  • Consider implementing a web application firewall or PHP security hardening rules to restrict object deserialization to trusted sources.

Generated by OpenCVE AI on October 10, 2026 at 08:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
Title WordPress Edema theme <= 1.2.2.2 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:37.796Z

Reserved: 2026-09-19T00:23:25.965Z

Link: CVE-2026-93941

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:06.557

Modified: 2026-10-10T08:17:06.557

Link: CVE-2026-93941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:45:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data