CVE-2025-32284: WordPress Pet World theme <= 2.8 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in designthemes Pet World allows Object Injection. This issue affects Pet World: from n/a through 2.8.
Other sources
Deserialization of Untrusted Data vulnerability in designthemes Pet World petsworld allows Object Injection.This issue affects Pet World: from n/a through <= 2.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32284?
CVE-2025-32284 is classified as a high-severity vulnerability due to its risk of object injection from deserialization of untrusted data.
How do I fix CVE-2025-32284?
To fix CVE-2025-32284, upgrade the DesignThemes Pet World plugin to version 2.9 or later.
What systems are affected by CVE-2025-32284?
CVE-2025-32284 affects versions of DesignThemes Pet World up to and including 2.8.
What type of vulnerability is CVE-2025-32284?
CVE-2025-32284 is a deserialization vulnerability that can lead to object injection.
Can CVE-2025-32284 be exploited remotely?
Yes, CVE-2025-32284 can be exploited remotely, potentially allowing attackers to execute malicious code.