CVE-2025-31422: WordPress Visual Art | Gallery WordPress Theme <= 2.4 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in designthemes Visual Art | Gallery WordPress Theme allows Object Injection. This issue affects Visual Art | Gallery WordPress Theme: from n/a through 2.4.
Other sources
Deserialization of Untrusted Data vulnerability in designthemes Visual Art | Gallery WordPress Theme visual-arts allows Object Injection.This issue affects Visual Art | Gallery WordPress Theme: from n/a through <= 2.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31422?
CVE-2025-31422 is considered a critical vulnerability due to its potential for object injection through deserialization of untrusted data.
How do I fix CVE-2025-31422?
To fix CVE-2025-31422, update the Visual Art | Gallery WordPress Theme to version 2.5 or later.
What is the impact of CVE-2025-31422 on my website?
CVE-2025-31422 can lead to remote code execution and potentially compromise your website's security.
Which versions of the Visual Art | Gallery WordPress Theme are affected by CVE-2025-31422?
CVE-2025-31422 affects all versions of the Visual Art | Gallery WordPress Theme from the initial release up to and including version 2.4.
How can I determine if my site is vulnerable to CVE-2025-31422?
If you are using the Visual Art | Gallery WordPress Theme version 2.4 or lower, your site is likely vulnerable to CVE-2025-31422.