
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67617 is a Deserialization of Untrusted Data vulnerability (PHP Object Injection) in the Consult Aid WordPress theme developed by themeton. It affects all versions of the theme up to and including 1.4.3. The vulnerability was published on January 22, 2026, with a CVSS v3.1 base score of 9.8 (Critical) assigned by CISA-ADP (NVD, Patchstack).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The flaw exists in the Consult Aid WordPress theme (versions ≤ 1.4.3), where user-supplied data is passed to PHP's deserialization routines without adequate validation or sanitization. An unauthenticated remote attacker can craft a malicious serialized PHP object and submit it over the network; if a suitable "gadget chain" exists within the WordPress installation or its plugins, this can be leveraged to achieve arbitrary code execution, file manipulation, or other impacts. No authentication or user interaction is required, and attack complexity is low (NVD, Patchstack).
Successful exploitation can result in full compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. An unauthenticated attacker may achieve remote code execution, manipulate or delete site data, exfiltrate sensitive information (including credentials stored in the database), or pivot to other systems hosted on the same server. The absence of any authentication requirement significantly broadens the attack surface to any internet-facing WordPress installation running the vulnerable theme (NVD, Patchstack).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (NVD, Patchstack).
unserialize() (e.g., using tools like PHPGGC).O:, a:, s: in request bodies or parameters); unexpected outbound connections from the web server process.unserialize() failures or unexpected class instantiation.wp-config.php or .htaccess.php, bash, curl, wget) performing network connections or file operations not consistent with normal CMS activity.No official patch has been confirmed as available for the Consult Aid theme at the time of reporting. Site administrators should immediately deactivate and remove the Consult Aid theme (versions ≤ 1.4.3) until a patched version is released by themeton. As interim mitigations, deploy a Web Application Firewall (WAF) configured to detect and block PHP object injection payloads, enforce strict input validation at the application layer, and monitor server logs for anomalous activity. Check the theme's official repository or the Patchstack database for patch availability (Patchstack).
The vulnerability was reported by Patchstack and noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of January 12–18, 2026. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database listings (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."