
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54719 is a Deserialization of Untrusted Data vulnerability (Object Injection) in the NooTheme "Yogi - Health Beauty & Yoga" WordPress theme (noo-yogi). It affects all versions up to and including 2.9.2, with version 2.9.3 being the first patched release. The vulnerability was reported on July 3, 2025, published by Patchstack on August 2, 2025, and registered in NVD on November 6, 2025. It carries a CVSS v3.1 base score of 8.8 (High), requiring only low-level (Subscriber) privileges to exploit over the network (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The theme fails to properly validate or sanitize serialized data before deserializing it, allowing an attacker with Subscriber-level access to inject malicious PHP objects into the application. Depending on available PHP classes (gadget chains) present in the WordPress environment, this object injection can be leveraged to trigger unintended code paths, potentially leading to arbitrary code execution, file manipulation, or denial of service. No user interaction is required, and the attack is conducted entirely over the network with low complexity (Patchstack).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress site. An authenticated attacker with minimal privileges (e.g., a Subscriber account) could inject malicious objects to execute arbitrary code, access or modify sensitive data, gain administrative access, or cause a denial of service. The scope is limited to the affected system, but compromise of the WordPress instance could enable further lateral movement within the hosting environment (Patchstack).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Patchstack). The EPSS score is approximately 0.048%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity.
wp-content/themes/noo-yogi/) or uploads directory; modification timestamps on theme files inconsistent with legitimate updates.bash, curl, wget, python) that are not part of normal WordPress operation.The primary remediation is to update the NooTheme Yogi - Health Beauty & Yoga WordPress theme to version 2.9.3 or later, which contains the fix for this vulnerability (Patchstack). As an interim measure for sites unable to update immediately, Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts. Additional hardening steps include disabling open user registration if not required, implementing strict input validation, and conducting a security audit of the WordPress installation. Limiting Subscriber-level access and monitoring for suspicious activity are also recommended.
The vulnerability was discovered and reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity on July 3, 2025, and disclosed by Patchstack on August 2, 2025 (Patchstack). No significant broader media coverage or notable social media discussion has been identified for this vulnerability beyond standard vulnerability database listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."