
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54001 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the ThemeREX Classter WordPress theme, affecting all versions through 2.5. It was reported on December 4, 2025 by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and publicly disclosed on March 3–5, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), exploitable remotely without authentication or user interaction (Patchstack, Feedly).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The Classter WordPress theme fails to safely handle serialized PHP data, allowing an unauthenticated remote attacker to inject a malicious serialized object. If a suitable PHP Object Injection (POP) chain exists within the application or its dependencies, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service (Patchstack). No authentication or user interaction is required, and attack complexity is low.
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress site. Depending on available POP chains, an attacker could achieve remote code execution, perform SQL injection, traverse the file system, or cause a denial of service condition. This could lead to full site compromise, data theft, defacement, or use of the server as a pivot point for further attacks (Patchstack, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this severity class are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).
O:, a:, s:) in POST bodies or query parameters directed at Classter theme endpoints.wp-content/themes/classter/) or uploads directory; modifications to existing theme files.bash, curl, wget) indicating potential code execution following deserialization.As of the disclosure date, no official patch from ThemeREX is available for the Classter theme (Patchstack). Patchstack has issued a virtual patch (mitigation rule) to block exploitation attempts for users of its service. Site administrators should consider disabling or removing the Classter theme until an official fix is released, implementing a web application firewall (WAF) to filter malicious serialized payloads, and restricting network access to affected WordPress installations. Monitor vendor channels for an updated version and apply it immediately upon release (Feedly).
Wordfence included CVE-2025-54001 in its weekly WordPress vulnerability report for March 2–8, 2026, highlighting it among notable disclosures (Wordfence Blog). The Hacker Wire published a dedicated article on the vulnerability (The Hacker Wire). Qualys included detection for this CVE (detection ID 531055) in its March 2026 application security detections release (Qualys).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."