Organizations Urged to Patch ThemeREX Let's Play v1.1.15 to Mitigate Critical 9.8 CVSS Deserialization Risk
A critical deserialization vulnerability in ThemeREX's Let's Play plugin allows attackers to inject objects, posing severe risks to web infrastructure.

Key points
- CVE-2026-93935 is rated 9.8 CVSS Critical by the NVD.
- The flaw affects ThemeREX Let's Play versions up to 1.1.15.
- The vulnerability involves deserialization of untrusted data.
Web platforms running ThemeREX's Let's Play plugin face immediate exposure to object injection attacks due to a critical deserialization flaw. The US National Vulnerability Database assigns CVE-2026-93935 a maximum severity score of 9.8, indicating a high likelihood of successful exploitation by remote attackers.
How it unfolded
- The National Vulnerability Database published the record for CVE-2026-93935, identifying a critical security weakness.
- Researchers categorised the issue as CWE-502, highlighting improper handling of untrusted data during deserialization processes.
- The disclosure confirms that versions of the Let's Play plugin up to 1.1.15 contain the unpatched vulnerability.
Who is affected
Organisations utilising the ThemeREX Group Let's Play plugin for their websites are directly affected by this disclosure. Any instance running version 1.1.15 or earlier is susceptible to the object injection attack described in the advisory. The vulnerability stems from the plugin's failure to properly validate data during deserialization, a common vector for remote code execution.
ThemeREX Group is the developer responsible for the Let's Play plugin, which is widely used in web design templates. The specific weakness, identified as CWE-502, allows attackers to inject malicious objects into the application's memory. This can lead to arbitrary code execution on the host server if the input is not adequately sanitised before processing.
The fix
No patch or security update has been confirmed by ThemeREX Group as of the publication of this report. Administrators should monitor official channels for vendor announcements regarding a remediation release. Until a fix is available, users of affected versions remain exposed to potential exploitation through the documented object injection pathway.
What to do and how to stay safe: ThemeREX
- Audit your web server for installations of ThemeREX Let's Play plugin version 1.1.15 or earlier.
- Restrict access to the affected application using firewall rules to limit exposure to untrusted networks.
- Monitor server logs for unusual deserialization attempts or unexpected object creation events.
- Once the vendor provides an update, apply it immediately to resolve the deserialization vulnerability.
Step-by-step guide: Patch Management: Eight Questions Answered for Stability
General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is the CVSS score for CVE-2026-93935?
The National Vulnerability Database rates CVE-2026-93935 with a CVSS score of 9.8, classifying it as Critical.
Which versions of the Let's Play plugin are vulnerable?
All versions of the ThemeREX Group Let's Play plugin from its initial release through version 1.1.15 are affected.
Is there a patch available for this vulnerability?
No fix has been confirmed yet; users must wait for ThemeREX to release an official security update.



