CVE-2025-39499: WordPress Medicare Theme <= 2.1.0 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in BoldThemes Medicare allows Object Injection.This issue affects Medicare: from n/a through 2.1.0.
Other sources
Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affects Medicare: from n/a through <= 2.1.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39499?
CVE-2025-39499 has been classified as a high severity vulnerability due to the potential for remote code execution through object injection.
How do I fix CVE-2025-39499?
To fix CVE-2025-39499, update the BoldThemes Medicare plugin or theme to version 2.1.1 or later.
What is the impact of CVE-2025-39499 on my site?
CVE-2025-39499 allows attackers to exploit a deserialization vulnerability, potentially leading to unauthorized access and execution of arbitrary code on your site.
Which versions of Medicare are affected by CVE-2025-39499?
CVE-2025-39499 affects BoldThemes Medicare versions up to and including 2.1.0.
Is CVE-2025-39499 an active threat?
While specific exploits for CVE-2025-39499 may not be widely reported, it is recommended to address it promptly to mitigate potential risk.