
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54723 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the BoldThemes DentiCare WordPress theme. It affects all DentiCare versions prior to 1.4.3 and allows unauthenticated remote attackers to perform object injection attacks. The vulnerability was reported on May 25, 2025, published by Patchstack on September 23, 2025, and assigned a CVE on December 18, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), classified under OWASP Top 10 A3: Injection and mapped to CAPEC-586 (Object Injection). An unauthenticated remote attacker can supply crafted serialized PHP data to the theme, which is deserialized without validation, allowing arbitrary PHP objects to be injected into the application. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress installation or its plugins, this can escalate to remote code execution, SQL injection, path traversal, or denial of service. No authentication or user interaction is required, and attack complexity is low (Patchstack).
Successful exploitation can result in full compromise of the affected WordPress site, including arbitrary code execution, unauthorized data access, SQL injection, path traversal, and denial of service — depending on available POP chains in the environment. All three security pillars are impacted at the highest level: confidentiality, integrity, and availability. Given the unauthenticated network-based attack vector, mass exploitation campaigns targeting thousands of WordPress sites simultaneously are a realistic threat (Patchstack).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns against WordPress sites. No threat actor attribution is available, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
/wp-content/themes/denticare/style.css).O:, a:, s: in POST bodies or query parameters); unexpected outbound connections from the web server process./wp-content/uploads/ or theme directories); unexpected changes to wp-config.php or .htaccess.bash, curl, wget, python) or unexpected database queries originating from the web application process.The primary remediation is to update the DentiCare WordPress theme to version 1.4.3 or later, which contains the patch for this vulnerability. Patchstack has also issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until the theme is updated. Additional hardening measures include implementing input validation for all deserialization processes, using safe deserialization methods that restrict object creation, applying the principle of least privilege to the web server and database accounts, and monitoring for unusual system behavior or unauthorized access attempts (Patchstack).
The vulnerability was credited to researcher 'Bonds' and disclosed through Patchstack's Vulnerability Disclosure Program (VDP). Wordfence also referenced this vulnerability in their weekly WordPress vulnerability report for the period of September 22–28, 2025. No significant broader media coverage or notable public researcher commentary beyond these security vendor reports has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."