CVE-2025-54719
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-54719 is a Deserialization of Untrusted Data vulnerability (Object Injection) in the NooTheme "Yogi - Health Beauty & Yoga" WordPress theme (noo-yogi). It affects all versions up to and including 2.9.2, with version 2.9.3 being the first patched release. The vulnerability was reported on July 3, 2025, published by Patchstack on August 2, 2025, and registered in NVD on November 6, 2025. It carries a CVSS v3.1 base score of 8.8 (High), requiring only low-level (Subscriber) privileges to exploit over the network (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The theme fails to properly validate or sanitize serialized data before deserializing it, allowing an attacker with Subscriber-level access to inject malicious PHP objects into the application. Depending on available PHP classes (gadget chains) present in the WordPress environment, this object injection can be leveraged to trigger unintended code paths, potentially leading to arbitrary code execution, file manipulation, or denial of service. No user interaction is required, and the attack is conducted entirely over the network with low complexity (Patchstack).

Impact

Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress site. An authenticated attacker with minimal privileges (e.g., a Subscriber account) could inject malicious objects to execute arbitrary code, access or modify sensitive data, gain administrative access, or cause a denial of service. The scope is limited to the affected system, but compromise of the WordPress instance could enable further lateral movement within the hosting environment (Patchstack).

Exploitability

As of the time of publication, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Patchstack). The EPSS score is approximately 0.048%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the NooTheme Yogi theme version ≤ 2.9.2 via passive scanning tools (e.g., WPScan, Shodan) or by inspecting theme metadata in page source.
  2. Obtain low-privilege access: Register or obtain a Subscriber-level account on the target WordPress site (e.g., via open registration).
  3. Identify the vulnerable deserialization endpoint: Locate the theme functionality that accepts and deserializes user-controlled serialized PHP data (e.g., a form field, cookie, or API parameter processed by the theme).
  4. Craft a malicious serialized payload: Using a PHP gadget chain tool (e.g., PHPGGC), generate a serialized PHP object payload targeting a gadget chain available in the WordPress/theme environment to achieve the desired effect (RCE, file write, etc.).
  5. Submit the payload: Send the crafted serialized payload to the vulnerable endpoint as an authenticated Subscriber user.
  6. Achieve objective: If a suitable gadget chain exists, the deserialized object triggers unintended PHP logic, potentially resulting in arbitrary code execution, web shell upload, or privilege escalation to administrator (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests from Subscriber-level accounts to theme-specific endpoints with unusual or binary-encoded data in request bodies or parameters.
  • File System: Unexpected PHP files (web shells) created in the WordPress theme directory (wp-content/themes/noo-yogi/) or uploads directory; modification timestamps on theme files inconsistent with legitimate updates.
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., bash, curl, wget, python) that are not part of normal WordPress operation.
  • Network: Outbound connections from the web server to unknown external IPs, particularly on non-standard ports, following authenticated requests to the site.

Mitigation and workarounds

The primary remediation is to update the NooTheme Yogi - Health Beauty & Yoga WordPress theme to version 2.9.3 or later, which contains the fix for this vulnerability (Patchstack). As an interim measure for sites unable to update immediately, Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts. Additional hardening steps include disabling open user registration if not required, implementing strict input validation, and conducting a security audit of the WordPress installation. Limiting Subscriber-level access and monitoring for suspicious activity are also recommended.

Community reactions

The vulnerability was discovered and reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity on July 3, 2025, and disclosed by Patchstack on August 2, 2025 (Patchstack). No significant broader media coverage or notable social media discussion has been identified for this vulnerability beyond standard vulnerability database listings.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18039NONEN/A
  • essential-addons-for-elementor-lite
NoYesAug 14, 2026
CVE-2026-16810NONEN/A
  • bit-form
NoYesAug 14, 2026
CVE-2026-16739NONEN/A
  • epeken-all-kurir
NoNoAug 14, 2026
CVE-2026-15205NONEN/A
  • paymob-for-woocommerce
NoYesAug 14, 2026
CVE-2026-14290NONEN/A
  • embed-google-photos-album-easily
NoNoAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management