CVE-2025-31924: WordPress Crafts & Arts theme <= 2.5 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts allows Object Injection. This issue affects Crafts & Arts: from n/a through 2.5.
Other sources
Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.This issue affects Crafts & Arts: from n/a through <= 2.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31924?
CVE-2025-31924 is considered a critical vulnerability due to its potential for object injection attacks.
How do I fix CVE-2025-31924?
To fix CVE-2025-31924, update the DesignThemes Crafts & Arts plugin to the latest version beyond 2.5.
What type of attack can CVE-2025-31924 facilitate?
CVE-2025-31924 can facilitate object injection attacks that may lead to remote code execution.
Which versions of Crafts & Arts are affected by CVE-2025-31924?
CVE-2025-31924 affects all versions of Crafts & Arts prior to and including version 2.5.
Is CVE-2025-31924 applicable to WordPress installations?
Yes, CVE-2025-31924 affects the Crafts & Arts theme used in WordPress up to version 2.5.