CVE-2025-60216
9.8BoldThemes · Addison
The BoldThemes Addison WordPress theme contains a PHP Object Injection vulnerability due to insecure deserialization, permitting unauthenticated remote code execution.
Executive summary
The BoldThemes Addison WordPress theme is subject to a critical PHP Object Injection vulnerability that allows for unauthenticated remote code execution.
Vulnerability
This is a Deserialization of Untrusted Data (CWE-502) vulnerability. The flaw can be exploited by an unauthenticated attacker, as confirmed by the CVSS attack vector (AV:N/PR:N/UI:N).
Business impact
Exploitation of this vulnerability could result in full site compromise, allowing attackers to execute commands, modify data, or exfiltrate sensitive information. The high CVSS score highlights the critical risk to organizational systems utilizing this theme.
Remediation
Immediate Action: Update the Addison theme to version 1.4.8 or later immediately.
Proactive Monitoring: Inspect server logs for suspicious activity, particularly requests that involve complex or serialized data structures targeting the theme's components.
Compensating Controls: Implement a Web Application Firewall (WAF) to inspect and block unauthorized deserialization attempts directed at the WordPress theme.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for full system compromise, users of the BoldThemes Addison theme must update to version 1.4.8 without delay.