Junglewise Threat Intelligence

CVE-2025-69108: ThemeREX Hot Coffee PHP Object Injection

CVE-2025-69108 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Hot Coffee theme for WordPress is vulnerable to a critical security flaw that allows attackers to inject malicious code without needing a password. This theme is used to design and manage the appearance of WordPress websites. If exploited, an attacker could take complete control of the website, steal sensitive customer data, or disrupt services entirely.

Technical details

A PHP Object Injection vulnerability exists in the ThemeREX Hot Coffee theme for WordPress (versions <= 1.7) due to improper deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, this can lead to remote code execution, SQL injection, or full site compromise. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • ThemeREX Hot Coffee <= 1.7

Timeline

  • 2025-10-15: other: Vulnerability reported by researcher
  • 2026-05-26: advisory: Patchstack published initial advisory
  • 2026-06-17: disclosed: CVE published to NVD

References