CVE-2025-54719
8.8NooTheme · Yogi - Health Beauty & Yoga
A deserialization of untrusted data vulnerability in the NooTheme Yogi theme allows for object injection, potentially leading to remote code execution.
Executive summary
The NooTheme Yogi theme is vulnerable to an object injection flaw that could allow an authenticated attacker to execute arbitrary code on the underlying server.
Vulnerability
The theme suffers from a deserialization of untrusted data flaw (CWE-502), which can be triggered by an authenticated user with low privileges to perform object injection.
Business impact
Successful exploitation of this vulnerability can lead to a complete compromise of the WordPress installation, including unauthorized access to sensitive data and the ability to execute arbitrary commands on the server. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to significant operational disruption and data loss.
Remediation
Immediate Action: Since a specific patch version is not currently identified, users should disable the Yogi theme or switch to a secure alternative until the vendor releases a fix.
Proactive Monitoring: Review application and web server access logs for unusual serialized data patterns or unauthorized administrative actions originating from low-privileged user accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect and block malicious serialized PHP objects in incoming HTTP requests.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a significant risk to site integrity and server security. Organizations utilizing the NooTheme Yogi theme must prioritize the immediate removal or restriction of the affected component until an official security update is verified and applied. Continuous monitoring of vendor communications for patch availability is essential.
More NooTheme CVEs
Sources
Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.