Junglewise Threat Intelligence

CVE-2025-60205: ThemeREX Addons PHP Object Injection

CVE-2025-60205 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

ThemeREX Addons is a WordPress plugin used to provide additional features and design elements for websites. A critical security flaw allows an unauthenticated attacker to remotely execute malicious code or gain full control over the website. This could lead to the theft of customer data, website defacement, or a total service outage.

Technical details

The ThemeREX Addons plugin for WordPress is vulnerable to PHP Object Injection in versions up to 2.36.1.1 due to the deserialization of untrusted data. An unauthenticated remote attacker can exploit this vulnerability by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker can achieve remote code execution, perform SQL injection, or conduct path traversal. The issue is resolved in version 2.36.2.

Affected products

  • ThemeREX ThemeREX Addons <= 2.36.1.1

Timeline

  • 2025-07-28: other: Vulnerability reported by researcher Bonds
  • 2025-08-27: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD/CVE record published

References