
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67619 is a Deserialization of Untrusted Data vulnerability (PHP Object Injection) in the designthemes Kids Heaven WordPress theme (slug: kids-world). It affects all versions of the theme through 3.2 and was disclosed on January 22, 2026, by Patchstack. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), assigned by CISA-ADP (NVD, Patchstack).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The Kids Heaven WordPress theme fails to properly validate or sanitize serialized data before passing it to PHP's deserialization functions, allowing an authenticated attacker with low privileges to supply a crafted serialized payload that instantiates arbitrary PHP objects. Depending on the PHP classes available in the application's scope (gadget chains), this object injection can be leveraged to achieve remote code execution, file manipulation, or other high-impact outcomes (NVD, Patchstack).
Successful exploitation grants an authenticated low-privileged attacker full confidentiality, integrity, and availability impact on the affected WordPress installation. An attacker could read sensitive data (e.g., database credentials, user information), modify or delete site content, and disrupt service availability. If a suitable PHP gadget chain exists in the environment, the vulnerability could escalate to remote code execution, enabling lateral movement within the hosting infrastructure (NVD).
As of the time of disclosure, no public proof-of-concept exploit code has been identified and there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.024% (0.000240), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at least a low-privileged authenticated account on the WordPress site, which somewhat limits the attack surface (NVD, Patchstack).
kids-world) version 3.2 or earlier, using tools like WPScan or Shodan with WordPress fingerprinting.unserialize()).O:, a:, s: patterns in request bodies or cookies).__wakeup/__destruct method calls.wp-content/themes/kids-world/) or uploads directory, particularly web shells (e.g., files with .php extension containing eval, base64_decode, or system calls).apache2, nginx, php-fpm) such as bash, curl, wget, or python.No patched version of the Kids Heaven theme has been confirmed as available at the time of disclosure. Site administrators should immediately audit whether the theme is in use and, if so, consider temporarily deactivating it until a patched version (above 3.2) is released by designthemes. As a compensating control, restrict WordPress user registration and limit authenticated access to trusted users only. Implement a Web Application Firewall (WAF) rule to block requests containing serialized PHP object patterns. Monitor the Patchstack advisory for patch availability updates (NVD).
The vulnerability was reported by Wordfence in their weekly WordPress vulnerability report covering January 12–18, 2026, which aggregates newly disclosed WordPress theme and plugin vulnerabilities. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database entries and aggregator reports.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."