
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67996 is a Deserialization of Untrusted Data (PHP Object Injection) vulnerability in the BoldThemes Nestin WordPress theme that allows unauthenticated remote attackers to perform object injection attacks. It affects all Nestin theme versions prior to 1.2.6 and was discovered and reported by João Pedro S Alcântara (Kinorth) on November 25, 2025, with public disclosure on February 9, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The Nestin WordPress theme fails to properly validate or sanitize serialized data before deserializing it, enabling an unauthenticated attacker to inject a malicious PHP object via a network request. If a suitable Property-Oriented Programming (POP) chain exists within the application or its dependencies, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service. No authentication or user interaction is required, and attack complexity is low (Patchstack, Red Hat CVE).
Successful exploitation of this vulnerability can result in complete system compromise with high impact to confidentiality, integrity, and availability. An unauthenticated attacker could execute arbitrary code, access or exfiltrate sensitive data, modify site content or databases, and disrupt service availability — all without any user interaction. The scope of impact depends on the presence of a usable POP chain in the target environment, but the potential for full WordPress site takeover and lateral movement within a shared hosting environment is significant (Patchstack).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as high priority and notes that vulnerabilities of this type are frequently used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack, Red Hat CVE).
style.css files.O:, a:, or s:) sent to Nestin theme endpoints; unexpected outbound connections from the web server to external IPs.wp-config.php or core WordPress files.bash, curl, wget, python) that are not typical for normal WordPress operation.The primary remediation is to update the BoldThemes Nestin WordPress theme to version 1.2.6 or later, which contains the patch for this vulnerability. Site administrators who cannot immediately update should contact their hosting provider or web developer for assistance. Patchstack has issued a virtual patch (mitigation rule) for subscribers to block exploitation attempts until the theme is updated. Additionally, implementing network segmentation, monitoring for suspicious deserialization activity, and ensuring no untrusted data is passed to deserialization functions are recommended defensive measures (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering February 9–15, 2026, highlighting it as part of broader WordPress ecosystem security coverage. Patchstack, which coordinated the disclosure, classified it as high priority and noted the potential for mass-exploit campaigns targeting WordPress sites at scale. No significant additional vendor statements or notable researcher commentary beyond the initial disclosure have been identified (Wordfence Weekly Report, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."