
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60215 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the Kriya WordPress theme developed by designthemes. It affects all versions of the Kriya theme up to and including version 3.4, and was first reported on May 25, 2025, by researcher "Bonds" via Patchstack, with public disclosure on June 24, 2025, and NVD publication on October 22, 2025. As of the time of reporting, no official patch has been released by the vendor. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), assessed by CISA-ADP (Patchstack, Feedly).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The Kriya theme fails to properly validate or sanitize user-supplied data before passing it to PHP's deserialization functions, allowing an attacker to inject a crafted serialized PHP object. Exploitation requires a low-privilege account (e.g., Subscriber-level WordPress user) and no user interaction, and is conducted entirely over the network. If a suitable PHP Object Injection (POP) chain exists within the WordPress environment — either in the theme itself or installed plugins — this can be leveraged to achieve code injection, SQL injection, path traversal, or denial of service (Patchstack).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress site. Depending on the POP chain available in the target environment, an attacker could achieve remote code execution, exfiltrate sensitive data, manipulate the database via SQL injection, traverse the file system, or cause a denial of service. The scope is limited to the affected system, but full site compromise — including administrative takeover — is a realistic outcome (Patchstack, Feedly).
As of the latest available information, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as high priority, noting that vulnerabilities of this type are frequently used in mass-exploit campaigns targeting WordPress sites at scale, and has issued a virtual patch (mitigation rule) for its users (Patchstack).
/wp-content/themes/kriya/style.css).O:, a:, s: in request bodies or cookies); unusual outbound connections from the web server process.unserialize() calls./wp-content/uploads/, /wp-content/themes/kriya/); modification timestamps on core or theme files inconsistent with legitimate updates.bash, curl, wget, python) indicating post-exploitation activity following successful object injection (Patchstack).No official patch from the vendor (designthemes) is available as of the latest reporting; the Kriya theme remains vulnerable through version 3.4. Patchstack has issued a virtual patch (mitigation rule) for its subscribers to block exploitation attempts until an official fix is released. Site administrators should consider temporarily deactivating the Kriya theme if no alternative protection is in place, applying the principle of least privilege to WordPress user roles, and monitoring for suspicious activity. Upgrading to a version beyond 3.4 — once released by the vendor — is the recommended long-term remediation (Patchstack).
Patchstack, which discovered and disclosed the vulnerability, has classified it as high priority and noted that PHP Object Injection vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites (Patchstack). The CVE was noted on Bluesky by automated CVE tracking accounts shortly after publication. No significant broader media coverage or vendor statement from designthemes has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."