CVE-2025-24779: WordPress Yogi theme < 2.9.3 - PHP Object Injection Vulnerability
Published Jul 16, 2025
·Updated
Deserialization of Untrusted Data vulnerability in NooTheme Yogi allows Object Injection. This issue affects Yogi: from n/a through 2.9.0.
Other sources
Deserialization of Untrusted Data vulnerability in NooTheme Yogi yogi allows Object Injection.This issue affects Yogi: from n/a through < 2.9.3.
— MITRE
Affected Software
1 affected component
NooTheme Yogi<=2.9.0, <2.9.3
Event History
Jul 16, 2025
CVE Published
via MITRE·11:28 AM
Data Sourced
via MITRE·11:28 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24779?
CVE-2025-24779 has a high severity rating due to its potential for object injection attacks.
2
How do I fix CVE-2025-24779?
To fix CVE-2025-24779, upgrade NooTheme Yogi to version 2.9.1 or later.
3
What types of systems are affected by CVE-2025-24779?
CVE-2025-24779 affects NooTheme Yogi versions up to and including 2.9.0 installed on WordPress.
4
What is the main issue with CVE-2025-24779?
CVE-2025-24779 primarily allows for deserialization of untrusted data, enabling object injection.
5
Is there a known exploit for CVE-2025-24779?
There are reports of exploits being developed for CVE-2025-24779, targeting vulnerable installations.