
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-31422 is a PHP Object Injection vulnerability caused by deserialization of untrusted data in the Visual Art | Gallery WordPress Theme developed by designthemes. It affects all versions of the theme from n/a through 2.4 (inclusive). The vulnerability was published on July 16, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 8.8 (High) (Red Hat CVE, ENISA EUVD).
The vulnerability is classified under CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The root cause is the theme's failure to properly validate or sanitize serialized data before passing it to PHP's deserialization functions, allowing an attacker to inject malicious PHP objects. Exploitation requires low-privilege network access (authenticated user), with no user interaction needed, making it accessible to any registered WordPress user. The attack vector is network-based with low complexity (Red Hat CVE, Patchstack).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress site. An attacker with low-privilege access could inject malicious PHP objects that, when combined with a suitable POP (Property-Oriented Programming) chain present in the application or its dependencies, may lead to arbitrary code execution, unauthorized access to sensitive data, or complete site compromise. The vulnerability scope is limited to the affected system but could serve as a foothold for broader lateral movement within a hosting environment (ENISA EUVD, Red Hat CVE).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. It was included in CISA's weekly vulnerability bulletin for the week of July 14, 2025 (CISA Bulletin, Red Hat CVE).
O:, a:, s: in request bodies or cookies).wp-content/themes/visual-arts/) or uploads directory; modification timestamps on core files inconsistent with update history.bash, curl, wget) following web requests to the WordPress installation.The primary remediation is to update the Visual Art | Gallery WordPress Theme to a version beyond 2.4, which addresses the deserialization vulnerability. As interim workarounds, administrators should implement strict input validation for any deserialization processes, use allow-lists for accepted object types, and restrict network access to the WordPress administration area. Regularly auditing and updating all installed WordPress themes and plugins is also strongly recommended (Patchstack, ENISA EUVD).
The vulnerability was reported by Patchstack and included in Wordfence's weekly WordPress vulnerability report for July 14–20, 2025, which aggregates notable WordPress security issues for the community (Wordfence Blog). It was also referenced in CISA's weekly vulnerability bulletin, indicating standard industry tracking. No notable individual researcher commentary or significant social media discussion has been identified beyond routine vulnerability aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."