
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69371 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the AncoraThemes KindlyCare WordPress theme, affecting all versions through 1.6.1. It allows unauthenticated remote attackers to inject malicious PHP objects, potentially leading to arbitrary code execution. The vulnerability was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on November 20, 2025, and published by Patchstack on January 29, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack, Feedly).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), classified under OWASP Top 10 A3: Injection and mapped to CAPEC-586 (Object Injection). An unauthenticated attacker can send a crafted network request containing a serialized PHP payload; when the theme deserializes this input without validation, it instantiates attacker-controlled objects. If a suitable PHP Object Property (POP) chain exists within the WordPress environment or installed plugins/themes, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service (Patchstack, Feedly).
Successful exploitation can result in full compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. An unauthenticated attacker could execute arbitrary code, access or exfiltrate sensitive data, modify site content, perform SQL injection, or cause a denial of service — all without requiring user interaction. The broad attack surface of WordPress hosting environments increases the risk of lateral movement to other hosted sites or underlying server infrastructure (Patchstack, Feedly).
No public proof-of-concept exploit or evidence of active in-the-wild exploitation has been observed as of the latest available data. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. No CISA KEV catalog entry exists for this CVE. However, Patchstack notes that vulnerabilities of this severity class (CVSS 9.8) are frequently used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack, Feedly).
__wakeup, __destruct, __toString) to build a Property-Oriented Programming (POP) chain suitable for the desired impact (e.g., RCE, file write).O:, a:, or base64-encoded variants); unexpected outbound connections from the web server process.unserialize() calls.wp-config.php or core WordPress files.bash, curl, wget, python) indicating post-exploitation activity.No official patch from AncoraThemes was available as of the publication date; the vulnerable version remains ≤ 1.6.1. Users should monitor the AncoraThemes repository for an updated release and upgrade immediately when available. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts. Additional workarounds include implementing web application firewall (WAF) rules to block serialized PHP object payloads, restricting network-level access to affected WordPress instances, and isolating the site from critical infrastructure until a patch is applied (Patchstack, Feedly).
Patchstack, which discovered and published the vulnerability, classified it as high priority and noted that vulnerabilities of this CVSS score are commonly leveraged in mass-exploit campaigns against WordPress sites. The Wordfence weekly WordPress vulnerability report for the period of January 26–February 1, 2026 also referenced this CVE, indicating broader community awareness within the WordPress security ecosystem (Wordfence Blog, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."