Junglewise Threat Intelligence

CVE-2025-69122: ThemeREX SeaFood Company PHP object injection

CVE-2025-69122 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The SeaFood Company theme for WordPress is vulnerable to a critical security flaw that allows unauthorized individuals to inject malicious code into a website. This theme is used to manage the visual layout and functionality of websites, particularly for food-related businesses. An attacker could exploit this to gain full control over the site, steal sensitive customer data, or cause a total service outage.

Technical details

A PHP Object Injection vulnerability exists in the ThemeREX SeaFood Company theme for WordPress in versions up to and including 1.4. The issue stems from the deserialization of untrusted data (CWE-502), which allows an unauthenticated remote attacker to inject arbitrary PHP objects. If a suitable Property-Oriented Programming (POP) chain is present within the environment, this can lead to remote code execution (RCE), SQL injection, or unauthorized file access. The attack is network-reachable and requires no user interaction or privileges. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • ThemeREX SeaFood Company <= 1.4

Timeline

  • 2025-10-15: other: Vulnerability reported by researcher
  • 2026-05-26: advisory: Patchstack published vulnerability details
  • 2026-06-17: disclosed: CVE published to NVD

References