CRITICAL
9.8 CVE-2026-93931 Published 10 Oct 2026
ThemeREX Smash Plugin Deserialization Object Injection Vulnerability
Worried this affects your website?
A Deserialization of Untrusted Data vulnerability has been found in ThemeREX Group Smash. The flaw allows Object Injection.
Affected versions:
- Smash from n/a through 1.12.0
Reference: CVE-2026-93931 on NVD
← Back to Security News