CVE-2025-32293: WordPress Finance Consultant theme <= 2.8 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant allows Object Injection. This issue affects Finance Consultant: from n/a through 2.8.
Other sources
Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant finance allows Object Injection.This issue affects Finance Consultant: from n/a through <= 2.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32293?
The severity of CVE-2025-32293 is classified as high due to its potential to allow Object Injection through deserialization of untrusted data.
How do I fix CVE-2025-32293?
To fix CVE-2025-32293, upgrade the DesignThemes Finance Consultant plugin to version 2.9 or later.
What systems are affected by CVE-2025-32293?
CVE-2025-32293 affects the DesignThemes Finance Consultant plugin versions up to and including 2.8.
What type of vulnerability is CVE-2025-32293?
CVE-2025-32293 is a deserialization of untrusted data vulnerability that allows for Object Injection.
Can CVE-2025-32293 be exploited remotely?
Yes, CVE-2025-32293 can be exploited remotely, allowing attackers to inject harmful objects into the application.