PatchSiren cyber security CVE debrief
CVE-2026-62087 ThemeREX CVE debrief
A critical vulnerability was found in the Equadio theme for WordPress, affecting versions up to 1.1.4. This vulnerability allows unauthenticated PHP object injection, which could potentially lead to severe consequences.
- Vendor
- ThemeREX
- Product
- Equadio
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations using the Equadio theme should assess exposure and apply remediation. The vulnerability's critical severity and potential for severe consequences necessitate high priority attention.
Why it matters
CVE-2026-62087 is a critical vulnerability in the Equadio theme for WordPress, allowing unauthenticated PHP object injection. Defenders should assess exposure and apply remediation due to the vulnerability's high severity and potential impact.
- Potential for severe consequences due to critical CVSS score
- Need for high priority assessment and remediation
- Potential impact on WordPress installations using the Equadio theme
Technical summary
The Equadio theme for WordPress, version up to 1.1.4, is vulnerable to unauthenticated PHP object injection. This vulnerability is tracked under CVE-2026-62087 and has a critical CVSS score of 9.8.
Defensive priority
High priority should be given to assessing exposure and applying remediation, as the vulnerability has a critical CVSS score of 9.8.
Recommended defensive actions
- Assess exposure of Equadio theme versions up to 1.1.4
- Apply remediation or patches provided by the vendor
- Monitor for potential exploitation attempts
Evidence notes
The vulnerability was reported by Patchstack and is tracked under CVE-2026-62087. The NVD entry is currently in the 'Received' status.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-62087 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-62087
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-62087 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62087
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.