CVE-2025-54001
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-54001 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the ThemeREX Classter WordPress theme, affecting all versions through 2.5. It was reported on December 4, 2025 by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and publicly disclosed on March 3–5, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), exploitable remotely without authentication or user interaction (Patchstack, Feedly).

Technical details

The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The Classter WordPress theme fails to safely handle serialized PHP data, allowing an unauthenticated remote attacker to inject a malicious serialized object. If a suitable PHP Object Injection (POP) chain exists within the application or its dependencies, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service (Patchstack). No authentication or user interaction is required, and attack complexity is low.

Impact

Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress site. Depending on available POP chains, an attacker could achieve remote code execution, perform SQL injection, traverse the file system, or cause a denial of service condition. This could lead to full site compromise, data theft, defacement, or use of the server as a pivot point for further attacks (Patchstack, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this severity class are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the ThemeREX Classter theme (version ≤ 2.5) via web fingerprinting tools such as WPScan or Shodan, looking for theme-specific file paths or metadata.
  2. Identify injection point: Locate the vulnerable endpoint or parameter in the Classter theme that accepts and deserializes user-supplied PHP serialized data without proper validation.
  3. Construct POP chain: Analyze the PHP classes available in the WordPress installation and its plugins/themes to identify a viable Property-Oriented Programming (POP) chain that can be triggered upon deserialization.
  4. Craft malicious payload: Serialize a PHP object that, when deserialized, triggers the POP chain to execute arbitrary code, perform SQL injection, or achieve another desired impact.
  5. Send crafted request: Submit the malicious serialized payload to the vulnerable endpoint as an unauthenticated HTTP request.
  6. Achieve objective: Depending on the POP chain, gain remote code execution, exfiltrate data, or cause denial of service on the target WordPress site (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests containing PHP serialized data patterns (e.g., strings beginning with O:, a:, s:) in POST bodies or query parameters directed at Classter theme endpoints.
  • Logs: WordPress or web server access logs showing repeated or anomalous requests to theme-specific PHP files with large or encoded payloads from unexpected IP addresses.
  • File System: Unexpected new PHP files (web shells) in the WordPress theme directory (wp-content/themes/classter/) or uploads directory; modifications to existing theme files.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget) indicating potential code execution following deserialization.
  • Database: Unexpected changes to WordPress database tables, new admin accounts, or injected malicious content in posts/options tables.

Mitigation and workarounds

As of the disclosure date, no official patch from ThemeREX is available for the Classter theme (Patchstack). Patchstack has issued a virtual patch (mitigation rule) to block exploitation attempts for users of its service. Site administrators should consider disabling or removing the Classter theme until an official fix is released, implementing a web application firewall (WAF) to filter malicious serialized payloads, and restricting network access to affected WordPress installations. Monitor vendor channels for an updated version and apply it immediately upon release (Feedly).

Community reactions

Wordfence included CVE-2025-54001 in its weekly WordPress vulnerability report for March 2–8, 2026, highlighting it among notable disclosures (Wordfence Blog). The Hacker Wire published a dedicated article on the vulnerability (The Hacker Wire). Qualys included detection for this CVE (detection ID 531055) in its March 2026 application security detections release (Qualys).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19859MEDIUM6.5
  • jetformbuilder
NoYesSep 06, 2026
CVE-2026-85038MEDIUM5.3
  • b2bking-wholesale-for-woocommerce
NoYesSep 06, 2026
CVE-2026-80439MEDIUM4.8
  • wpcf7-redirect
NoYesSep 06, 2026
CVE-2026-80437MEDIUM4.8
  • ninja-forms
NoYesSep 06, 2026
CVE-2026-19862MEDIUM4.8
  • jetformbuilder
NoYesSep 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management