
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68903 is a PHP Object Injection vulnerability caused by deserialization of untrusted data in the AivahThemes Anona WordPress theme. It affects all versions of the Anona theme through version 8.0 and was reported by researcher Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on September 11, 2025, with public disclosure on January 13–22, 2026. As of the time of reporting, no official patch is available from the vendor. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), assigned by CISA-ADP (Patchstack, NVD).
The vulnerability is classified under CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The Anona theme fails to properly validate or sanitize serialized PHP data before deserializing it, allowing an authenticated attacker with low privileges (e.g., Subscriber role) to pass malicious serialized objects to the application. If a suitable PHP Object/POP (Property-Oriented Programming) chain exists within the WordPress environment, this can be leveraged to achieve code injection, SQL injection, path traversal, or denial of service (Patchstack).
Successful exploitation can result in complete compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. An authenticated attacker could execute arbitrary code, access or exfiltrate sensitive data, modify site content or configurations, and potentially disrupt site availability. The presence of a suitable POP chain in the environment further amplifies the risk, potentially enabling lateral movement within the hosting infrastructure (Patchstack).
No public proof-of-concept exploit code has been identified, and there is no confirmed evidence of in-the-wild exploitation at this time. The vulnerability requires low-privilege authentication (Subscriber level), making it accessible to a broad range of potential attackers on sites with open user registration. The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns once weaponized (Patchstack).
O: or a: in request bodies or parameters).bash, curl, wget) indicating potential code execution following deserialization.No official patch from AivahThemes is available for the Anona theme as of the disclosure date. Site administrators should consider disabling or replacing the Anona theme until a patched version is released. Access to theme functionality should be restricted to trusted administrators, and open user registration should be disabled if not required. Patchstack has issued a virtual patch (mitigation rule) for subscribers of its service to block exploitation attempts. Monitoring for suspicious deserialization activity and object instantiation is also recommended (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report for the week of January 12–18, 2026, highlighting it as part of broader WordPress ecosystem security coverage. Patchstack, which discovered and disclosed the vulnerability, issued a virtual patch for its users given the absence of an official fix. No significant broader media coverage or notable researcher commentary beyond these sources has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."