External risk intelligence

ThemeREX Booklovers Object Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-62045

The vulnerability affects a WordPress theme, which is by definition a web-facing component of a website. Publicly accessible websites are commonly deployed as internet-facing services, making the vulnerable deserialization point reachable via the internet.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves a weakness in the Booklovers theme that could allow unauthorized code execution if a malicious actor provides specially crafted data. The potential impact is significant, as it could lead to a complete compromise of the affected system. The main concern is confirming relevance and exposure.

  • Untrusted data can execute malicious code.
  • Critical flaw could impact any system using it.
  • Confirm if our systems are exposed to this risk.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted data to a website using the vulnerable ThemeREX Group Booklovers theme. This data, when processed by the theme, can lead to the injection of malicious objects. If successful, this could allow an attacker to execute arbitrary code on the server, leading to a complete compromise of the website.

  • The vulnerability is reachable via the network.
  • Specially crafted data triggers deserialization.
  • Enables remote code execution and site compromise.

Live Threat

Current exploitation, exposure, and threat context

A deserialization vulnerability in the Booklovers theme could allow an attacker to inject objects into the system. This could lead to unauthorized actions on the website when supported by the advisory and when the theme's code processes user-supplied data that is then deserialized.

  • Theme's object handling may be compromised.
  • Untrusted data could be processed.
  • Site integrity may be impacted.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Booklovers theme likely requires action from the application owner and potentially the platform or infrastructure team. The first practical step is to identify all instances of the Booklovers theme within your WordPress deployments. Confirm which of these instances are externally facing or host critical business data, then identify the accountable owner for each to prioritize remediation efforts.

  • Application owners should investigate deployments.
  • Verify external accessibility and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Booklovers theme and what is it used for?

Booklovers is a WordPress theme developed by ThemeREX Group, commonly used to build and design the front-end interface of websites. It provides the layout, styling, and structural components that determine how site visitors interact with and view content, making it a central part of the web server's application layer.

What does Object Injection mean in CVE-2026-62045?

This vulnerability is classified as CWE-502, or Deserialization of Untrusted Data. It means the software takes incoming data from a user and converts it into complex objects without sufficient verification. An attacker can manipulate this data to inject unauthorized objects, which can force the application to perform unintended actions or execute malicious code.

How is this vulnerability triggered?

The flaw is triggered when the Booklovers theme processes specifically crafted, malicious data sent from an external source. It does not trigger during normal, legitimate site navigation or when the theme handles standard, expected inputs. The issue requires the application to perform the deserialization process on the attacker-supplied, harmful data payload.

Why is this considered an internet-facing risk?

According to Halo Surface Signal, this vulnerability is highly relevant because it resides within a WordPress theme, which by design must be accessible to the public internet to function. Because the deserialization point is reachable over the network by any visitor, an attacker does not need prior internal access to attempt an injection.

How should I respond if I use the Booklovers theme?

Begin by auditing your WordPress environments to identify every instance where the Booklovers theme is installed. Once you have a complete inventory, prioritize these assets based on their accessibility to the internet and the sensitivity of the data they host. Identify the individuals responsible for these specific sites so you can coordinate the necessary updates to secure the software.

References