
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69404 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the ThemeREX Extreme Store WordPress theme that enables PHP Object Injection. It affects Extreme Store versions up to and including 1.5.10, requiring no authentication or user interaction to exploit. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, Wordfence).
The root cause is unsafe deserialization of user-supplied data within the ThemeREX Extreme Store WordPress theme, classified as CWE-502 (Deserialization of Untrusted Data) and mapped to CAPEC-586 (Object Injection). An unauthenticated remote attacker can send specially crafted serialized PHP objects to the application, which are then deserialized without proper validation, potentially triggering a PHP Object Injection chain. Exploitation requires no privileges and no user interaction, making the attack surface fully network-accessible (Feedly, Patchstack).
Successful exploitation can result in complete compromise of the affected WordPress installation, with high impact to confidentiality, integrity, and availability. Depending on available PHP gadget chains present in the WordPress environment, an attacker may achieve arbitrary code execution, read or exfiltrate sensitive data, modify or delete site content, or cause a denial of service. The unauthenticated nature of the vulnerability significantly broadens the potential attacker pool and risk of mass exploitation (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Feedly).
O:, a:, s: in request bodies or cookies); unexpected outbound connections from the web server to external IPs.wp-config.php or core WordPress files.bash, curl, wget, python) indicating potential code execution following deserialization.Site administrators should update the ThemeREX Extreme Store theme to a version beyond 1.5.10 as soon as a patched release is available from the vendor. Until a patch is confirmed, consider disabling or removing the theme if it is not critical to operations, and implement a Web Application Firewall (WAF) rule to block requests containing serialized PHP object patterns. Restrict network access to the WordPress admin interface and monitor for suspicious deserialization-related activity in server logs (Feedly, Wordfence).
Wordfence included CVE-2025-69404 in its weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as a notable critical issue for WordPress site operators (Wordfence). Patchstack has also catalogued the vulnerability in its WordPress vulnerability database (Patchstack). No significant broader media coverage or notable researcher commentary beyond these standard security community disclosures has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."