CVE-2025-31634: WordPress Insurance theme <= 3.5 - PHP Object Injection Vulnerability
Published Oct 22, 2025
·Updated
Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue affects Insurance: from n/a through <= 3.5.
Affected Software
2 affected components
DesignThemes Insurance<=3.5
WordPress Insurance theme<=3.5
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-31634?
CVE-2025-31634 is classified as a high severity vulnerability due to its potential for object injection attacks.
2
How do I fix CVE-2025-31634?
To resolve CVE-2025-31634, update the DesignThemes Insurance theme to version 3.6 or later.
3
What types of data are affected by CVE-2025-31634?
CVE-2025-31634 affects untrusted data during the deserialization process, leading to potential object injection.
4
What versions of DesignThemes Insurance are impacted by CVE-2025-31634?
CVE-2025-31634 impacts all versions of DesignThemes Insurance up to and including version 3.5.
5
Is CVE-2025-31634 related to WordPress themes?
Yes, CVE-2025-31634 is specifically related to the WordPress Insurance theme and its vulnerability to object injection.