
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25360 is a Deserialization of Untrusted Data vulnerability (PHP Object Injection) in the rascals Vex WordPress theme. It affects all versions of the Vex theme prior to 1.2.9. The vulnerability was published on March 25, 2026, with the fix available in version 1.2.9. It carries a CVSS v3.1 base score of 8.8 (High), exploitable by a low-privileged remote attacker with no user interaction required (Feedly, Patchstack).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), which enables PHP Object Injection (CAPEC-586). When the Vex theme deserializes attacker-controlled input without adequate validation or sanitization, an attacker can craft a malicious serialized PHP object and submit it to the application. Depending on the PHP classes available in the application's scope (so-called "gadget chains"), this can be leveraged to trigger arbitrary code execution, file manipulation, or other unintended behaviors. The attack requires only low-level authentication and is conducted over the network with no user interaction (Feedly, Patchstack).
Successful exploitation can result in full compromise of confidentiality, integrity, and availability of the affected WordPress installation. An attacker with low privileges could inject malicious PHP objects that, via available gadget chains, lead to remote code execution, unauthorized file read/write, or data exfiltration. In a shared hosting environment, this could also facilitate lateral movement to other hosted sites or server-level compromise (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.024%, indicating a low current probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVE was assigned and disclosed by Patchstack (Feedly, Patchstack).
/wp-content/themes/vex/style.css).O:, a:, s:) in parameters handled by the Vex theme; unexpected outbound connections from the web server to external IPs.unserialize() calls.wp-content/themes/vex/ or wp-content/uploads/); presence of web shells or unfamiliar scripts.php, bash, curl, wget) performing unusual actions such as network connections or file writes.The primary remediation is to upgrade the Vex WordPress theme to version 1.2.9 or later, which contains the fix for this vulnerability. For environments where immediate patching is not feasible, implement network-level access controls to restrict who can send requests to the WordPress installation, and apply the principle of least privilege to WordPress user roles. Additionally, consider using a Web Application Firewall (WAF) with rules to detect and block PHP object injection payloads as a temporary compensating control (Feedly, Patchstack).
The vulnerability was covered in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the period of March 16–22, 2026, highlighting it among other WordPress theme and plugin vulnerabilities disclosed that week (Wordfence). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."