Skip to content
LatestBlock Object Injection in Booklovers Theme by Verifying Version Before 2.13.1
Vulnerabilities

Block Object Injection in Booklovers Theme by Verifying Version Before 2.13.1

The NVD rates CVE-2026-62045 as critical because it allows unauthenticated attackers to inject objects via deserialization flaws in older Booklovers versions.

Block Object Injection in Booklovers Theme by Verifying Version Before 2.13.1
Illustration: Vector Update

Key points

  • The National Vulnerability Database assigned CVE-2026-62045 to the Booklovers WordPress theme developed by ThemeREX Group.
  • The flaw is rated 9.8 on the CVSS scale, which classifies it as critical due to the ease of exploitation and high impact.
  • All versions of the theme up to and including version 2.13.0 are affected by this deserialization of untrusted data vulnerability.
  • The underlying weakness is categorized under CWE-502, indicating that the application processes untrusted data without sufficient validation.

System administrators must immediately audit their WordPress installations to identify any sites running the Booklovers theme in version 2.13.0 or earlier. The National Vulnerability Database published CVE-2026-62045 to warn operators about a severe object injection flaw in this popular design template. This vulnerability allows attackers to exploit the theme’s data handling mechanisms without needing user credentials or prior access to the site. The exposure exists because the theme processes incoming data streams without verifying their integrity or origin before converting them into executable objects within the PHP environment.

In plain English

This security issue stems from how the Booklovers theme handles incoming information. The theme accepts data from external sources and attempts to convert that data into active code objects. This process is called deserialization. When an application deserializes data without checking if it is trustworthy, it creates a dangerous opening for malicious actors. An attacker can craft a specific packet of data that looks like normal input but actually contains hidden instructions. When the theme processes this fake data, it executes those hidden instructions as if they were legitimate parts of the website.

The background

ThemeREX Group developed the Booklovers theme for WordPress sites. The National Vulnerability Database records show that the flaw affects all versions of the theme released up to 2.13.0. The Common Weakness Enumeration identifies this specific problem as CWE-502, which stands for deserialization of untrusted data. This category of vulnerability is common in web applications that rely on complex data structures. The CVSS score of 9.8 indicates that the vulnerability is extremely severe. This high score reflects both the low skill level required to exploit the flaw and the potentially catastrophic impact on the affected server.

What changes now

Administrators need to verify the exact version of the Booklovers theme installed on every server under their control. Since the vulnerability allows for object injection, the potential consequences include remote code execution or complete system compromise. The National Vulnerability Database does not specify a fixed version in this record, only that versions through 2.13.0 are vulnerable. Operators should monitor official channels from ThemeREX Group for a patched release. Until a confirmed secure version is available, restricting access to the theme’s configuration endpoints may reduce the attack surface.

What to do and how to stay safe: Booklovers

  • Check your WordPress dashboard or server files to confirm the installed version of the Booklovers theme is not 2.13.0 or older.
  • Review server logs for unusual POST requests targeting the Booklovers theme files, which may indicate exploitation attempts.
  • Implement web application firewalls to filter out malformed data packets that resemble object injection payloads.
  • Contact your hosting provider to inquire about server-side restrictions that can limit PHP deserialization functions for this specific theme.

Step-by-step guide: Risk-Based Vulnerability Management: Benefits, Limits, and Reality

General security guidance from the Vector Update newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is the CVE ID for the Booklovers theme vulnerability?

The National Vulnerability Database assigned CVE-2026-62045 to this specific object injection flaw in the Booklovers theme.

Which versions of the Booklovers theme are affected by CVE-2026-62045?

All versions of the ThemeREX Group Booklovers theme up to and including version 2.13.0 are affected by this critical vulnerability.

How severe is the CVE-2026-62045 flaw according to the NVD?

The NVD rates the vulnerability as critical with a CVSS score of 9.8, indicating a high severity risk to affected systems.

Sources

  1. CVE Program
BookloversThemeREX GroupCVE-2026-62045WordPressCWE-502

Related stories