Sceawere
Vulnerability Detail
CVE-2026-62045UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Object Injection in Booklovers Theme
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 2h ago
- Vendor
- ThemeREX Group
- Product
- Booklovers
- Attack Type
- Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-10T08:17:04.647Z",
"pubdate": "2026-10-10T08:17:04.647Z",
"executiveSummary": "The Booklovers WordPress theme, developed by ThemeREX Group, is susceptible to a deserialization of untrusted data vulnerability, specifically classified as an Object Injection flaw.\nThis vulnerability exists within versions ranging from n/a through 2.13.0. The flaw allows remote, unauthenticated attackers to supply malicious serialized data to the application, which is then improperly processed by the theme's underlying codebase.\nSuccessful exploitation of this vulnerability can lead to critical security compromises, including arbitrary code execution (ACE), unauthorized access to sensitive application data, or complete denial of service (DoS) depending on the available gadget chains present within the environment.\nThe risk implication is high, as the vulnerability resides in a core component of the theme, potentially exposing the entire WordPress instance to remote exploitation without requiring prior authentication or administrative privileges.\nAttackers can leverage this flaw by injecting crafted serialized objects into specific entry points processed by the theme, triggering unintended execution paths.",
"technicalDetails": "The vulnerability originates from the insecure handling of serialized PHP data within the ThemeREX Booklovers theme. PHP's unserialize() function, when utilized on user-supplied input without rigorous validation or signature verification, is inherently dangerous.\nIn the context of the Booklovers theme, the application fails to sanitize or validate the data stream before passing it to the unserialize() operation. This allows an attacker to inject arbitrary serialized PHP objects into the application memory space.\nThe exploitation relies on the existence of 'gadget chains'—a sequence of class methods that, when triggered during or after the deserialization process, perform unintended actions. Because the application logic expects specific object structures, the injection of malicious serialized objects can force the application to instantiate classes in an unsafe state.\nThe attack flow proceeds as follows: 1) The attacker identifies an application endpoint or parameter that accepts serialized data as input. 2) The attacker constructs a malicious payload utilizing existing classes within the WordPress core, the theme itself, or active plugins to construct a functional gadget chain. 3) The payload is transmitted to the server via HTTP request parameters (e.g., POST/GET). 4) Upon receipt, the vulnerable function processes the payload via unserialize(), which triggers the magic methods (e.g., __wakeup, __destruct, or __toString) defined in the target classes. 5) The execution of these magic methods results in the arbitrary execution of code, manipulation of internal variables, or deletion of sensitive files, depending on the structure of the gadget chain.\nThis vulnerability is particularly severe because it bypasses conventional input sanitization that focuses on HTML or script injection. Instead, it operates at the object-serialization level, allowing for direct interaction with the underlying PHP environment. The lack of adequate authentication requirements means that any remote entity capable of reaching the vulnerable endpoint can initiate the attack. Post-exploitation impact varies based on the gadget chains available in the specific environment, but typically includes full system compromise, data exfiltration, or persistence through the injection of malicious configuration objects."
}