CVE-2025-54001: WordPress Classter theme <= 2.5 - PHP Object Injection vulnerability
Published Mar 5, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects Classter: from n/a through <= 2.5.
Affected Software
2 affected components
ThemeREX Classter<=2.5
WordPress Classter<=2.5
Event History
Mar 5, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-54001?
CVE-2025-54001 is classified as a critical severity vulnerability due to its potential for PHP Object Injection.
2
How do I fix CVE-2025-54001?
To fix CVE-2025-54001, update the ThemeREX Classter theme to version 2.6 or higher.
3
What versions are affected by CVE-2025-54001?
CVE-2025-54001 affects ThemeREX Classter versions up to and including 2.5.
4
What is the impact of CVE-2025-54001?
The impact of CVE-2025-54001 includes potential remote code execution and unauthorized access to sensitive data.
5
Who should be concerned about CVE-2025-54001?
Users and administrators of the ThemeREX Classter theme on WordPress should be concerned about CVE-2025-54001 due to its critical nature.