PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-62087 ThemeREX CVE debrief

A critical vulnerability was found in the Equadio theme for WordPress, affecting versions up to 1.1.4. This vulnerability allows unauthenticated PHP object injection, which could potentially lead to severe consequences.

Vendor
ThemeREX
Product
Equadio
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations using the Equadio theme should assess exposure and apply remediation. The vulnerability's critical severity and potential for severe consequences necessitate high priority attention.

Why it matters

CVE-2026-62087 is a critical vulnerability in the Equadio theme for WordPress, allowing unauthenticated PHP object injection. Defenders should assess exposure and apply remediation due to the vulnerability's high severity and potential impact.

  • Potential for severe consequences due to critical CVSS score
  • Need for high priority assessment and remediation
  • Potential impact on WordPress installations using the Equadio theme

Technical summary

The Equadio theme for WordPress, version up to 1.1.4, is vulnerable to unauthenticated PHP object injection. This vulnerability is tracked under CVE-2026-62087 and has a critical CVSS score of 9.8.

Defensive priority

High priority should be given to assessing exposure and applying remediation, as the vulnerability has a critical CVSS score of 9.8.

Recommended defensive actions

  • Assess exposure of Equadio theme versions up to 1.1.4
  • Apply remediation or patches provided by the vendor
  • Monitor for potential exploitation attempts

Evidence notes

The vulnerability was reported by Patchstack and is tracked under CVE-2026-62087. The NVD entry is currently in the 'Received' status.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-62087 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-62087

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-62087 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62087

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.