
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60237 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the Themeton Finag WordPress theme that enables PHP Object Injection. It affects Finag versions from n/a through 1.5.0 and was published on March 19, 2026, with Patchstack credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), reflecting its unauthenticated, network-exploitable nature (Red Hat CVE, ENISA EUVD).
The root cause is improper deserialization of untrusted user-supplied data within the Themeton Finag WordPress theme (CWE-502 / CAPEC-586: Object Injection). An attacker can send a crafted serialized PHP payload over the network to a vulnerable endpoint exposed by the theme, causing the application to instantiate arbitrary PHP objects. No authentication, elevated privileges, or user interaction is required, making this exploitable by any remote unauthenticated attacker. The vulnerability was reported through Patchstack's coordinated disclosure program (Patchstack, ENISA EUVD).
Successful exploitation can result in complete system compromise, with high impact to confidentiality, integrity, and availability. An attacker may achieve remote code execution by chaining the injected PHP object with available "gadget chains" in the WordPress environment, potentially leading to unauthorized access to sensitive data, modification of site content and configurations, and full denial of service. Given the WordPress ecosystem's shared hosting prevalence, exploitation could also facilitate lateral movement to co-hosted sites or server-level compromise (ENISA EUVD, The Hacker Wire).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (ENISA EUVD). The EPSS score is approximately 0.041%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. However, the unauthenticated, network-accessible attack vector and critical CVSS score make it a high-priority target if a gadget chain is identified in the WordPress environment.
style.css files./wp-admin/admin-ajax.php) or theme-specific endpoints containing serialized PHP data patterns (e.g., strings beginning with O:, a:, s: typical of PHP serialization).unserialize() calls./wp-content/uploads/) or theme directory, particularly files with webshell characteristics (e.g., eval, base64_decode, system function calls).apache2, nginx, php-fpm) such as bash, curl, wget, or python; outbound network connections from the web server to unknown external IPs.Users should upgrade the Themeton Finag WordPress theme to a version newer than 1.5.0 as soon as a patched release becomes available from the vendor. Until a patch is released, administrators should implement network-level controls to restrict access to the WordPress installation, apply a Web Application Firewall (WAF) rule to detect and block serialized PHP payloads in requests, and consider temporarily deactivating the Finag theme if it is not critical to operations. Monitoring for unusual file system changes and unexpected outbound connections from the web server is also recommended (ENISA EUVD, Patchstack).
The vulnerability received coverage from The Hacker Wire and was noted on social platforms including Mastodon and Bluesky shortly after disclosure (The Hacker Wire, Mastodon). Patchstack, which coordinated the disclosure, published the vulnerability in its WordPress security database. No significant vendor statements from Themeton or broader community debate have been observed beyond standard vulnerability aggregation and reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."