Junglewise Threat Intelligence

CVE-2025-69127: ThemeREX Plumbing PHP Object Injection

CVE-2025-69127 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Plumbing theme for WordPress is vulnerable to a critical security flaw that allows unauthorized attackers to inject malicious code into a website. This could lead to a total takeover of the site, theft of customer data, or a complete service outage. Because this vulnerability can be exploited without any login credentials, it is a high-priority risk for businesses using this theme.

Technical details

The Plumbing theme (also known as Plumbing Parts) for WordPress contains a PHP Object Injection vulnerability in versions up to and including 1.6. The flaw stems from the deserialization of untrusted data (CWE-502) without proper validation. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, SQL injection, or arbitrary file access. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • ThemeREX Plumbing (Plumbing Parts) <= 1.6

Timeline

  • 2025-10-15: other: Vulnerability reported by researcher
  • 2026-05-26: advisory: Patchstack published initial advisory
  • 2026-06-17: disclosed: CVE published to NVD

References