Vex < 1.2.9 - Authenticated (Subscriber+) PHP Object Injection
highThe Vex theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.2.9 via deserialization of untrusted input [from the vulnerable parameter?|in the vulnerable function?]. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP...
- CVSS:
- 7.5
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9
- Disclosed:
- Mar 20, 2026