
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69099 is a Deserialization of Untrusted Data (PHP Object Injection) vulnerability in the fuelthemes North WordPress theme (north-wp). It affects all versions of the North theme through 5.7.5 and was published on January 22, 2026, with the CVE assigned by Patchstack. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), as assessed by CISA-ADP (Feedly, Patchstack).
The root cause is improper deserialization of user-supplied data (CWE-502), which allows an authenticated attacker with low privileges to inject malicious PHP objects into the application. This class of vulnerability (CAPEC-586: Object Injection) typically arises when PHP's unserialize() function processes attacker-controlled input without validation, enabling the attacker to instantiate arbitrary objects and potentially chain PHP gadgets to achieve code execution. Exploitation requires network access and a low-privilege authenticated session, but no user interaction or special configuration is needed (Feedly, Patchstack).
Successful exploitation can result in full compromise of the affected WordPress site, impacting confidentiality, integrity, and availability. An authenticated attacker with low privileges could achieve remote code execution by leveraging PHP object injection gadget chains present in the WordPress environment, potentially enabling data theft, site defacement, backdoor installation, or lateral movement within the hosting environment (Feedly).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2025-69099. The EPSS score is approximately 0.024%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (Feedly).
unserialize() function — typically a form field, cookie, or API parameter handled by the North theme.O:<length>:"<classname>") in parameters handled by the North theme; repeated login attempts from unfamiliar IPs followed by theme-related requests./wp-content/themes/north-wp/) or uploads directory; modification timestamps on theme files inconsistent with legitimate updates.php, bash, curl, wget) executing commands not typical of normal WordPress operation.Users should immediately upgrade the fuelthemes North theme beyond version 5.7.5 to a patched release — contact fuelthemes or check the Patchstack database for the latest available version. If an upgrade is not immediately available, consider temporarily deactivating the North theme and switching to an alternative until a patch is released. Additionally, restrict user registration and minimize the number of low-privilege accounts, implement a Web Application Firewall (WAF) with rules targeting PHP object injection patterns, and review access logs for signs of exploitation (Feedly, Patchstack).
The vulnerability was reported by Wordfence in their weekly WordPress vulnerability report covering January 12–18, 2026, and was tracked in the Patchstack database. No significant independent researcher commentary or broad media coverage has been identified beyond standard vulnerability database listings (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."