CVE-2025-32928: WordPress Altair theme <= 5.2.2 - PHP Object Injection vulnerability
Published May 19, 2025
·Updated
Deserialization of Untrusted Data vulnerability in ThemeGoods Altair altair allows Object Injection.This issue affects Altair: from n/a through <= 5.2.2.
Affected Software
3 affected components
ThemeGoods Altair Wordpress<=5.2.2
ThemeGoods Altair<=5.2.2
WordPress Altair theme<=5.2.2
Event History
May 19, 2025
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-32928?
CVE-2025-32928 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-32928?
To fix CVE-2025-32928, update the ThemeGoods Altair to the latest version beyond 5.2.2.
3
What is the impact of CVE-2025-32928?
CVE-2025-32928 can lead to object injection attacks that may compromise your application and data.
4
Which versions are affected by CVE-2025-32928?
CVE-2025-32928 affects ThemeGoods Altair versions from n/a up to 5.2.2 and the WordPress Altair theme of the same version.
5
Is CVE-2025-32928 a common vulnerability?
CVE-2025-32928 is a known vulnerability specific to the ThemeGoods Altair theme that has been publicly disclosed.