CVE-2025-31047: WordPress Themify Edmin theme <= 2.0.0 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection.This issue affects Themify Edmin: from n/a through 2.0.0.
Other sources
Deserialization of Untrusted Data vulnerability in Themify Themify Edmin edmin allows Object Injection.This issue affects Themify Edmin: from n/a through <= 2.0.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31047?
CVE-2025-31047 has a high severity due to its potential for object injection and remote code execution.
How do I fix CVE-2025-31047?
To remediate CVE-2025-31047, update Themify Edmin to version 2.0.1 or later.
What types of systems are affected by CVE-2025-31047?
CVE-2025-31047 affects all versions of Themify Edmin up to and including 2.0.0.
What is the main issue associated with CVE-2025-31047?
The main issue of CVE-2025-31047 is the deserialization of untrusted data, leading to potential object injection.
Can exploitation of CVE-2025-31047 be mitigated?
Exploitation of CVE-2025-31047 can be mitigated by disabling features that handle untrusted data until the software is updated.