CVE-2025-52828: WordPress Red Art theme <= 3.8 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in designthemes Red Art allows Object Injection. This issue affects Red Art: from n/a through 3.7.
Other sources
Deserialization of Untrusted Data vulnerability in designthemes Red Art redart allows Object Injection.This issue affects Red Art: from n/a through <= 3.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52828?
CVE-2025-52828 has been classified as a high-severity vulnerability due to the potential for remote code execution through object injection.
How do I fix CVE-2025-52828?
To mitigate CVE-2025-52828, update the DesignThemes Red Art plugin to version 3.8 or later where the vulnerability has been resolved.
Who is affected by CVE-2025-52828?
CVE-2025-52828 affects users of DesignThemes Red Art version 3.7 and earlier.
What type of vulnerability is CVE-2025-52828?
CVE-2025-52828 is a deserialization of untrusted data vulnerability allowing for object injection.
Is CVE-2025-52828 a common vulnerability?
CVE-2025-52828 is a specific vulnerability related to the Red Art theme, but object injection vulnerabilities are common in various software applications.