Skip to main content
Vulnerability Database/CVE-2026-62105

CVE-2026-62105: ThemeREX Addons PHP Object Injection Flaw

CVE-2026-62105 is an unauthenticated PHP object injection vulnerability in ThemeREX Addons plugin affecting versions below 2.45.0. This flaw enables attackers to inject malicious objects without authentication. This article covers technical details, affected versions, security impact, and recommended mitigation strategies.

Published:

CVE-2026-62105 Overview

CVE-2026-62105 is an unauthenticated PHP Object Injection vulnerability affecting the ThemeREX Addons WordPress plugin in versions prior to 2.45.0. The flaw is classified under [CWE-502: Deserialization of Untrusted Data] and permits remote attackers to inject arbitrary serialized PHP objects without authentication. Attackers can leverage the injection to trigger PHP magic methods within available gadget chains. Successful exploitation can result in remote code execution, arbitrary file operations, or full site compromise on affected WordPress installations.

Critical Impact

An unauthenticated remote attacker can inject serialized PHP objects into vulnerable ThemeREX Addons endpoints, enabling code execution or full compromise when a suitable gadget chain is present.

Affected Products

  • ThemeREX Addons WordPress plugin (trx_addons) versions prior to 2.45.0
  • WordPress sites bundling ThemeREX commercial themes that ship the plugin
  • Any hosting environment exposing the vulnerable plugin endpoints to the public internet

Discovery Timeline

  • 2026-09-11 - CVE-2026-62105 published to the National Vulnerability Database
  • 2026-09-11 - Last updated in NVD database

Technical Details for CVE-2026-62105

Vulnerability Analysis

The vulnerability resides in the ThemeREX Addons plugin (trx_addons), which passes attacker-controlled input into a PHP unserialize() call. Because the deserialization occurs before authentication, any remote client can submit crafted serialized data to the vulnerable endpoint. PHP reconstructs objects during deserialization and invokes magic methods such as __wakeup(), __destruct(), or __toString() on the resulting instances. When gadget chains exist in loaded plugins, themes, or WordPress core, this behavior can be escalated into arbitrary file writes, SQL execution, or command execution. The plugin is bundled with numerous ThemeREX commercial themes, expanding the exposed attack surface across WordPress deployments.

Root Cause

The root cause is the use of PHP's unserialize() on untrusted input without validation, sanitization, or use of safer alternatives such as json_decode(). The plugin does not enforce authentication or capability checks on the affected code path, so requests originate from the unauthenticated network attack surface. This pattern aligns with [CWE-502] and is a recurring issue in WordPress plugin ecosystems where object injection intersects with widely available gadget chains.

Attack Vector

Exploitation is performed over the network by sending a crafted HTTP request to a vulnerable ThemeREX Addons endpoint. The request payload contains a serialized PHP object designed to instantiate classes with exploitable magic methods. No user interaction and no prior authentication are required. The Patchstack advisory documents the affected code path and version boundary. See the Patchstack Vulnerability Report for the technical write-up.

Detection Methods for CVE-2026-62105

Indicators of Compromise

  • HTTP requests to trx_addons plugin endpoints containing serialized PHP payloads recognizable by patterns such as O: (object), a: (array), or s: (string) tokens in parameters.
  • Unexpected PHP files, webshells, or modified theme files appearing under wp-content/ after requests to the plugin.
  • New or modified WordPress administrator accounts created without a corresponding audit trail.
  • Outbound network connections from the web server to unknown hosts following requests to plugin endpoints.

Detection Strategies

  • Inspect web server and WAF logs for POST or GET parameters containing serialized PHP object markers directed at /wp-content/plugins/trx_addons/ paths.
  • Alert on PHP processes spawning shell interpreters (sh, bash, python) from the web server user context.
  • Correlate anomalous file creation events under WordPress directories with preceding HTTP requests to the plugin.

Monitoring Recommendations

  • Enable detailed HTTP access logging with full request bodies on WordPress front-ends running ThemeREX themes.
  • Monitor plugin and theme file integrity using tooling such as wp-cli checksums or a file integrity monitor.
  • Track the plugin version deployed across your fleet and alert when any host reports a version below 2.45.0.

How to Mitigate CVE-2026-62105

Immediate Actions Required

  • Upgrade the ThemeREX Addons (trx_addons) plugin to version 2.45.0 or later on every WordPress site.
  • Audit wp-content/ for unauthorized files, modified themes, and unexpected administrator accounts created before patching.
  • Rotate WordPress secrets in wp-config.php, database credentials, and administrator passwords if compromise is suspected.

Patch Information

The vendor addressed the vulnerability in ThemeREX Addons version 2.45.0. Administrators should update through the WordPress admin dashboard or by replacing the plugin directory with the patched release. Confirm the fix by verifying the plugin version reported under the Plugins screen. Details are available in the Patchstack Vulnerability Report.

Workarounds

  • Deploy a Web Application Firewall rule that blocks HTTP requests containing serialized PHP object patterns targeting trx_addons endpoints.
  • Restrict access to the plugin's endpoints at the web server level until patching is complete.
  • Temporarily deactivate the ThemeREX Addons plugin if the theme functionality is not business-critical.
bash
# Update ThemeREX Addons via wp-cli
wp plugin update trx_addons --version=2.45.0
wp plugin list --name=trx_addons --fields=name,status,version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.