CVE-2025-47584: WordPress Photography theme <= 7.5.2 - PHP Object Injection vulnerability
Published Jun 6, 2025
·Updated
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2.
Affected Software
3 affected components
ThemeGoods Photography<=7.5.2
WordPress Photography theme<=7.5.2
ThemeGoods Photography Wordpress<=7.7.2
Event History
Jun 6, 2025
CVE Published
via MITRE·11:45 AM
Data Sourced
via MITRE·11:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47584?
CVE-2025-47584 has a high severity rating due to its potential to allow remote code execution through deserialization of untrusted data.
2
How do I fix CVE-2025-47584?
To fix CVE-2025-47584, update the ThemeGoods Photography plugin to version 7.5.3 or later.
3
What versions are affected by CVE-2025-47584?
CVE-2025-47584 affects ThemeGoods Photography versions up to and including 7.5.2.
4
What is the impact of CVE-2025-47584 on my website?
The impact of CVE-2025-47584 can include unauthorized access, data manipulation, or remote code execution.
5
Is CVE-2025-47584 specific to any platform?
Yes, CVE-2025-47584 is specific to the ThemeGoods Photography plugin used in WordPress.