← back
CVE-2025-60225criticalCWE-502

WordPress BugsPatrol theme <= 1.5.0 - PHP Object Injection vulnerability

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.6%
exploitation probability
0.6%top 57% of all CVEs
observed exploitation
nono source reports it
In short

The BugsPatrol WordPress theme before version 1.5.1 has a flaw where it processes untrusted data without proper validation, allowing attackers to inject malicious objects into the system. This can lead to remote code execution and full compromise of the website.

Technical detail

The vulnerability exists in unsafe PHP deserialization of untrusted input, allowing remote attackers to instantiate arbitrary objects. No authentication is required; the attack vector is network-based via crafted serialized data. Successful exploitation results in arbitrary code execution with web server privileges.

Summary generated and translated by AI from the official description.
Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue affects BugsPatrol: from n/a through <= 1.5.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H