PHP Object Injection Vulnerability in ThemeREX Addons by ThemeREX
CVE-2025-60205
9.8CRITICAL
What is CVE-2025-60205?
ThemeREX Addons versions up to 2.36.1.1 are susceptible to a PHP Object Injection vulnerability that allows unauthenticated attackers to exploit the application. This flaw may enable attackers to execute arbitrary PHP code, leading to potential data breaches and site compromise. It is crucial for users and administrators of affected versions to apply available updates to mitigate risks.
Affected Version(s)
ThemeREX Addons <= 2.36.1.1