CVE-2025-67617
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67617 is a Deserialization of Untrusted Data vulnerability (PHP Object Injection) in the Consult Aid WordPress theme developed by themeton. It affects all versions of the theme up to and including 1.4.3. The vulnerability was published on January 22, 2026, with a CVSS v3.1 base score of 9.8 (Critical) assigned by CISA-ADP (NVD, Patchstack).

Technical details

The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The flaw exists in the Consult Aid WordPress theme (versions ≤ 1.4.3), where user-supplied data is passed to PHP's deserialization routines without adequate validation or sanitization. An unauthenticated remote attacker can craft a malicious serialized PHP object and submit it over the network; if a suitable "gadget chain" exists within the WordPress installation or its plugins, this can be leveraged to achieve arbitrary code execution, file manipulation, or other impacts. No authentication or user interaction is required, and attack complexity is low (NVD, Patchstack).

Impact

Successful exploitation can result in full compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. An unauthenticated attacker may achieve remote code execution, manipulate or delete site data, exfiltrate sensitive information (including credentials stored in the database), or pivot to other systems hosted on the same server. The absence of any authentication requirement significantly broadens the attack surface to any internet-facing WordPress installation running the vulnerable theme (NVD, Patchstack).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (NVD, Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Consult Aid theme (version ≤ 1.4.3) via passive techniques such as HTTP response headers, HTML source inspection, or tools like WPScan.
  2. Gadget chain identification: Enumerate installed WordPress plugins and themes on the target to identify available PHP gadget chains that can be triggered via unserialize() (e.g., using tools like PHPGGC).
  3. Payload crafting: Use PHPGGC or a custom script to generate a serialized PHP object payload targeting an identified gadget chain that achieves the desired effect (e.g., remote code execution, file write).
  4. Payload delivery: Submit the crafted serialized payload to the vulnerable input vector in the Consult Aid theme (the specific parameter or endpoint is not publicly documented) via an unauthenticated HTTP request.
  5. Achieve objective: If a suitable gadget chain is present, the deserialized object triggers the chain, resulting in arbitrary code execution, web shell upload, or data exfiltration on the target server (NVD, Patchstack).

Indicators of compromise

  • Network: Unusual or malformed POST requests to WordPress theme endpoints containing serialized PHP data (e.g., strings beginning with O:, a:, s: in request bodies or parameters); unexpected outbound connections from the web server process.
  • Logs: Web server access logs showing repeated requests to theme-specific endpoints with large or encoded payloads; PHP error logs referencing unserialize() failures or unexpected class instantiation.
  • File System: Newly created or modified PHP files in the WordPress theme or uploads directory (potential web shells); unexpected changes to wp-config.php or .htaccess.
  • Process: Unusual child processes spawned by the web server (e.g., php, bash, curl, wget) performing network connections or file operations not consistent with normal CMS activity.

Mitigation and workarounds

No official patch has been confirmed as available for the Consult Aid theme at the time of reporting. Site administrators should immediately deactivate and remove the Consult Aid theme (versions ≤ 1.4.3) until a patched version is released by themeton. As interim mitigations, deploy a Web Application Firewall (WAF) configured to detect and block PHP object injection payloads, enforce strict input validation at the application layer, and monitor server logs for anomalous activity. Check the theme's official repository or the Patchstack database for patch availability (Patchstack).

Community reactions

The vulnerability was reported by Patchstack and noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of January 12–18, 2026. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database listings (Wordfence Blog).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management