Convex Plugin Deserialization Vulnerability Enables Remote Object Injection on WordPress Sites
Deserialization of untrusted data in the Convex plugin exposes WordPress sites to remote object injection attacks requiring immediate attention.

Key points
- National Vulnerability Database rates CVE-2026-93943 as critical with a CVSS score of 9.8
- The flaw allows object injection via deserialization of untrusted data
- All versions of the ThemeREX Convex plugin up to and including 1.16.0 are affected
The ThemeREX Group Convex plugin contains a critical security flaw enabling object injection. The National Vulnerability Database identified this deserialization vulnerability as CVE-2026-93943. Security teams must assess their WordPress installations immediately to determine exposure levels and potential impact on their environments.
Root cause
The underlying issue stems from improper handling of serialized data within the plugin code. According to the NVD record, the weakness aligns with CWE-502, deserialization of untrusted data. This allows an attacker to inject malicious objects into the application memory space during the deserialization process.
Attack path
Exploiting this vulnerability requires sending crafted serialized data to the vulnerable plugin endpoint. The system fails to validate the integrity of the incoming data stream. Successful exploitation results in object injection, potentially leading to remote code execution depending on the specific configuration of the target WordPress installation.
Affected versions
The vulnerability impacts all iterations of the ThemeREX Convex plugin released prior to a secure update. Specifically, versions from the initial release through version 1.16.0 are confirmed vulnerable. No later versions are listed as unaffected in the current advisory.
Mitigation
- Audit all WordPress sites for the presence of the ThemeREX Convex plugin
- Verify the installed version against the affected range of 1.16.0 and earlier
- Remove the plugin if it is no longer required for site functionality
- Monitor server logs for unusual serialized data payloads or injection attempts
What to do and how to stay safe: ThemeREX
- Check your plugin inventory for any instance of the ThemeREX Convex component
- Review recent access logs for suspicious POST requests targeting plugin endpoints
- Ensure your WordPress core and other plugins are updated to reduce lateral movement risks
- Prepare an incident response plan in case of confirmed exploitation on affected servers
General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is the CVSS score for CVE-2026-93943?
The National Vulnerability Database assigns a CVSS score of 9.8, classifying it as critical severity.
Which specific versions of the Convex plugin are vulnerable?
All versions from the initial release up to and including version 1.16.0 are affected by this object injection flaw.
What type of vulnerability is described in the NVD record?
The record describes a deserialization of untrusted data vulnerability, specifically categorized under CWE-502 allowing object injection.



