CVE-2025-52724: WordPress Amwerk theme <= 1.2.0 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk allows Object Injection. This issue affects Amwerk: from n/a through 1.2.0.
Other sources
Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects Amwerk: from n/a through <= 1.2.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52724?
CVE-2025-52724 has a medium severity level due to the risk of object injection from deserialization of untrusted data.
How do I fix CVE-2025-52724?
To fix CVE-2025-52724, upgrade BoldThemes Amwerk to a version higher than 1.2.0.
What versions of BoldThemes Amwerk are affected by CVE-2025-52724?
All versions of BoldThemes Amwerk up to and including 1.2.0 are affected by CVE-2025-52724.
What type of vulnerability is CVE-2025-52724?
CVE-2025-52724 is a deserialization of untrusted data vulnerability that allows for object injection.
Is WordPress Amwerk also affected by CVE-2025-52724?
Yes, WordPress Amwerk versions up to and including 1.2.0 are vulnerable to CVE-2025-52724.