Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Deserialization of untrusted data in the Convex theme allows an attacker to instantiate arbitrary PHP objects, potentially leading to remote code execution. The flaw is cataloged as CWE-502 and scored 9.8 on CVSS, indicating a critical vulnerability. The vulnerability arises from the theme’s handling of user‑supplied serialized data without proper validation or sanitization.

Affected Systems

All WordPress sites using ThemeREX Group’s Convex theme version 1.16.0 or earlier are affected. The problem exists in all documented releases up to and including 1.16.0, irrespective of the WordPress core version.

Risk and Exploitability

Given the CVSS score of 9.8, the risk to affected installations is very high. The EPSS score is not available, so the exact likelihood of exploitation remains uncertain, but the absence of KEV listing does not mean the vulnerability is not being used; attackers could craft HTTP requests targeting the theme’s serialization logic. Because the flaw involves PHP object injection, a successful exploit would give the attacker code execution privileges on the server, compromising confidentiality, integrity, and availability of the entire WordPress installation.

Generated by OpenCVE AI on October 10, 2026 at 08:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Convex theme to a version newer than 1.16.0 immediately.
  • If an update cannot be performed right away, examine and restrict any PHP serialization endpoints provided by the theme and enforce strict input validation on data that may be deserialized.
  • Strengthen WordPress file and user permissions, ensure the site runs with the least privileges necessary, and monitor logs for anomalous PHP execution or file modifications.

Generated by OpenCVE AI on October 10, 2026 at 08:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
Title WordPress Convex theme <= 1.16.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:38.253Z

Reserved: 2026-09-19T00:23:25.965Z

Link: CVE-2026-93943

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:06.803

Modified: 2026-10-10T08:17:06.803

Link: CVE-2026-93943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:45:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data