CVE-2025-47579: WordPress Photography Theme <= 7.7.2 - PHP Object Injection Vulnerability
Published Sep 9, 2025
·Updated
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2.
Affected Software
3 affected components
ThemeGoods Photography<=7.5.2
WordPress Photography<=7.5.2
ThemeGoods Photography Wordpress<=7.7.2
Event History
Sep 9, 2025
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 6, 58279
Event
via MITRE·11:47 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-47579?
CVE-2025-47579 has a critical severity level, indicating a significant risk of exploitation.
2
How do I fix CVE-2025-47579?
To fix CVE-2025-47579, update ThemeGoods Photography to version 7.5.3 or later.
3
What systems are affected by CVE-2025-47579?
CVE-2025-47579 affects all versions of ThemeGoods Photography up to and including 7.5.2.
4
What kind of vulnerability is CVE-2025-47579?
CVE-2025-47579 is a Deserialization of Untrusted Data vulnerability.
5
Can CVE-2025-47579 be exploited remotely?
Yes, CVE-2025-47579 can potentially be exploited remotely without authentication.