CVE-2025-24779

8.8

NooTheme · Yogi

A deserialization of untrusted data vulnerability in the NooTheme Yogi WordPress theme allows for arbitrary object injection.

Executive summary

The NooTheme Yogi theme is vulnerable to object injection, which could allow an authenticated attacker to achieve remote code execution or other malicious impacts.

Vulnerability

This vulnerability involves the insecure deserialization of untrusted data (CWE-502). The flaw requires an authenticated user with low privileges to trigger the injection, which can lead to significant system compromise.

Business impact

The ability to perform object injection poses a severe risk to the confidentiality, integrity, and availability of the affected WordPress environment. With a CVSS score of 8.8, this high-severity flaw could allow attackers to execute arbitrary code, manipulate application logic, or gain unauthorized access to sensitive data. If left unpatched, this vulnerability could lead to a full site takeover or significant operational downtime.

Remediation

Immediate Action: Since a specific patch version is not currently listed, administrators should check the vendor website for the latest version of the Yogi theme and apply updates immediately. If no update is available, consider disabling the theme until a secure version is released.

Proactive Monitoring: Monitor server access logs for suspicious serialized strings or unusual requests directed at the theme directory. Implement integrity monitoring to detect unauthorized file modifications.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common object injection patterns and suspicious payloads targeting WordPress themes.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score of 8.8, this vulnerability represents a significant risk to the security of your WordPress installation. Administrators must prioritize monitoring for vendor updates and apply the latest version of the NooTheme Yogi theme as soon as it becomes available to remediate this critical deserialization flaw.

More NooTheme CVEs

Sources

Originally found and disclosed by Bonds | Patchstack Bug Bounty Program, per the CVE Program record.