
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69294 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) affecting the fuelthemes PeakShops WordPress theme. It allows authenticated attackers with low privileges (Contributor/Developer level) to inject malicious PHP objects into the application. All versions through 1.5.9 are affected, and no official patch is currently available. It carries a CVSS v3.1 base score of 8.8 (High) (Patchstack, Feedly).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The flaw exists in the PeakShops WordPress theme's handling of user-supplied data, which is deserialized without adequate validation, enabling PHP object injection. An authenticated attacker with Contributor or Developer privileges can craft a malicious serialized PHP object and submit it over the network; if a suitable PHP Object Property (POP) chain exists within the application or its dependencies, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service. No user interaction is required beyond the attacker's own authenticated session (Patchstack).
Successful exploitation can result in full compromise of confidentiality, integrity, and availability of the affected WordPress site. Depending on available POP chains, an attacker may achieve remote code execution, exfiltrate sensitive data, manipulate the database via SQL injection, traverse the file system, or cause a denial of service. The impact extends to all data stored on the WordPress instance, including user credentials, payment information, and site content (Patchstack, Feedly).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack, Feedly).
O: or a: patterns in request bodies or cookies).unserialize() calls.bash, curl, wget) following web requests to the PeakShops theme.siteurl, admin_email) (Patchstack).No official patch from fuelthemes is currently available for PeakShops. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators should restrict access to PeakShops instances to trusted networks, limit user registration and role assignment (especially Contributor/Developer roles), and monitor for suspicious activity. If the theme is not essential, consider deactivating or replacing it. Contact fuelthemes directly to inquire about patch availability and upgrade timelines (Patchstack, Feedly).
The vulnerability was discovered and reported by security researcher João Pedro S Alcântara (Kinorth) on November 14, 2025, and published by Patchstack on January 23, 2026. Wordfence also covered it in their weekly WordPress vulnerability report for the week of January 19–25, 2026. No significant broader media coverage or notable social media discussion has been identified beyond these security community sources (Patchstack, Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."