CVE-2025-53586: WordPress WeMusic Theme <= 1.9.1 - PHP Object Injection Vulnerability
Published Nov 6, 2025
·Updated
Deserialization of Untrusted Data vulnerability in NooTheme WeMusic noo-wemusic allows Object Injection.This issue affects WeMusic: from n/a through <= 1.9.1.
Affected Software
2 affected components
NooTheme WeMusic<=1.9.1
WordPress WeMusic Theme<=1.9.1
Event History
Nov 6, 2025
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Nov 30, 58290
Event
via MITRE·05:23 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-53586?
CVE-2025-53586 is classified as a critical vulnerability due to its potential for allowing object injection and deserialization of untrusted data.
2
How do I fix CVE-2025-53586?
To fix CVE-2025-53586, upgrade the NooTheme WeMusic plugin to version 1.9.2 or later.
3
What versions of NooTheme WeMusic are affected by CVE-2025-53586?
CVE-2025-53586 affects NooTheme WeMusic versions up to and including 1.9.1.
4
Can CVE-2025-53586 lead to remote code execution?
Yes, CVE-2025-53586 can potentially lead to remote code execution due to its nature of allowing object injection.
5
Is CVE-2025-53586 specific to WordPress installations?
CVE-2025-53586 specifically affects the WeMusic theme used on WordPress installations.