CVE-2025-32283: WordPress Solar Energy theme <= 3.5 - PHP Object Injection Vulnerability
Published Oct 22, 2025
·Updated
Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue affects Solar Energy: from n/a through <= 3.5.
Affected Software
1 affected component
DesignThemes Solar Energy<=3.5
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-32283?
CVE-2025-32283 has a critical severity level due to its potential for remote code execution.
2
How do I fix CVE-2025-32283?
To fix CVE-2025-32283, update the Solar Energy theme to a version greater than 3.5.
3
What type of vulnerability is CVE-2025-32283?
CVE-2025-32283 is a Deserialization of Untrusted Data vulnerability allowing for Object Injection.
4
Which versions of the Solar Energy theme are affected by CVE-2025-32283?
CVE-2025-32283 affects the Solar Energy theme versions from n/a up to and including 3.5.
5
Who is the vendor for the Solar Energy theme associated with CVE-2025-32283?
The vendor for the Solar Energy theme associated with CVE-2025-32283 is DesignThemes.