
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52724 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the BoldThemes Amwerk WordPress theme, affecting all versions up to and including 1.2.0. The vulnerability was reported by security researcher "Bonds" on June 8, 2025, and publicly disclosed on July 1, 2025, with the CVE published on June 27, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical), requiring no authentication or user interaction for exploitation (Patchstack, Red Hat CVE).
The root cause is improper deserialization of untrusted data (CWE-502), classified under OWASP Top 10 A3: Injection and mapped to CAPEC-586 (Object Injection). An unauthenticated remote attacker can supply a crafted serialized PHP object to the vulnerable theme, which is deserialized without validation, enabling object injection. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress installation or its plugins, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service (Patchstack).
Successful exploitation can lead to complete compromise of the affected WordPress site. Depending on available POP chains in the environment, an attacker could execute arbitrary code, perform SQL injection, traverse the file system, exfiltrate sensitive data, or cause a denial of service — all without any authentication. The network-accessible attack vector and lack of required user interaction make this vulnerability particularly dangerous for mass-exploitation campaigns targeting WordPress sites at scale (Patchstack).
No public proof-of-concept exploit code has been identified at this time, and there is no confirmed evidence of in-the-wild exploitation. The EPSS score is 0.00038, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack rates it as high priority and notes that vulnerabilities of this class are frequently used in mass-exploit campaigns against WordPress sites (Patchstack).
O:<length>:"<classname>":{...}) in POST body or GET parameters directed at the WordPress site running the Amwerk theme.wp-content/uploads; modifications to existing theme or core files with injected code.bash, curl, wget) indicating command execution via a POP chain.The patched version of the Amwerk WordPress theme is 1.3.0; all site administrators should update immediately from versions ≤ 1.2.0. If an immediate update is not possible, consider temporarily disabling the theme and switching to a safe alternative. Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until the theme is updated. Additionally, deploying a Web Application Firewall (WAF) with rules targeting PHP object injection patterns and implementing strict input validation for deserialization processes are recommended defensive measures (Patchstack).
The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the period of June 30 – July 6, 2025, and was referenced in the CISA Vulnerability Summary Bulletin (SB25-181) for the week of June 23, 2025. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregation coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."