Skip to content
firewallpulse
Bits, bytes and breaking security news
Vulnerabilities

Travesia WordPress Theme CWE-502 Deserialization Vulnerability CVE-2026-93929 Hits v1.1.16 and Older

A critical object injection vulnerability in the Travesia WordPress theme allows untrusted data deserialization, affecting versions through 1.1.16 with a CVSS score of 9.8.

Travesia WordPress Theme CWE-502 Deserialization Vulnerability CVE-2026-93929 Hits v1.1.16 and Older
Illustration: Firewall Pulse

Key points

  • CVE-2026-93929 is rated Critical with a CVSS score of 9.8 by the NVD.
  • The flaw stems from CWE-502 Deserialization of Untrusted Data in the Travesia theme.
  • All versions of the ThemeREX Group Travesia theme up to and including 1.1.16 are affected.

The Travesia WordPress theme contains a critical deserialization vulnerability that permits object injection. The National Vulnerability Database assigned CVE-2026-93929 to this issue, rating it with a CVSS score of 9.8. This high severity score indicates that the flaw is easily exploitable and could lead to significant damage if triggered successfully. Security teams must assess their WordPress installations for this specific theme version immediately.

Root cause

The underlying weakness is classified as CWE-502, Deserialization of Untrusted Data. The Travesia theme fails to properly validate or sanitize data before deserializing it. This lack of validation allows an attacker to inject malicious objects into the application’s memory space. Consequently, the application executes code defined by the attacker rather than legitimate application logic. This structural flaw exists within the core theme files provided by ThemeREX Group.

Attack path

An attacker can exploit this object injection flaw by supplying crafted data to the vulnerable theme components. Because the theme deserializes untrusted data without adequate checks, the attacker can manipulate the application state. This potentially allows for remote code execution or privilege escalation, depending on the specific context of the deserialization. The NVD record confirms that this issue affects the Travesia theme directly, bypassing standard input validation measures.

Affected versions

  • Travesia theme version 1.1.16
  • All versions prior to 1.1.16
  • The vulnerability exists from the initial release through version 1.1.16

Mitigation

  • Verify the installed version of the Travesia WordPress theme on all servers.
  • Check for any official patches or updates released by ThemeREX Group.
  • Monitor server logs for unusual deserialization errors or unexpected object creation.
  • Restrict access to administrative interfaces to reduce the attack surface temporarily.

What to do and how to stay safe: Travesia

  • Audit your WordPress environment to identify any sites using the Travesia theme.
  • Check the current theme version against the affected range of up to 1.1.16.
  • Review server access logs for signs of exploitation attempts related to object injection.
  • Prepare to apply an update once the vendor provides a confirmed fix for CVE-2026-93929.

Step-by-step guide: Out-of-band patches: what small businesses need to know

General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Which WordPress theme is affected by CVE-2026-93929?

The Travesia theme developed by ThemeREX Group is affected by this vulnerability.

What is the severity rating of this deserialization flaw?

The NVD rates CVE-2026-93929 as Critical with a CVSS score of 9.8.

Are there any confirmed patches for this issue yet?

No fix has been confirmed yet; users should monitor for updates from the vendor.

Sources

  1. CVE Program
TravesiaThemeREX GroupCVE-2026-93929WordPressDeserializationCWE-502

Related stories