CVE-2025-60212: WordPress VEDA Theme <= 4.2 - PHP Object Injection Vulnerability
Published Oct 22, 2025
·Updated
Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection.This issue affects VEDA: from n/a through <= 4.2.
Affected Software
2 affected components
DesignThemes VEDA<=4.2
WordPress VEDA Theme<=4.2
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-60212?
CVE-2025-60212 is classified as a high severity vulnerability due to its potential for remote code execution via object injection.
2
How do I fix CVE-2025-60212?
To fix CVE-2025-60212, update the DesignThemes VEDA to the latest version beyond 4.2 to mitigate the object injection vulnerability.
3
What versions are affected by CVE-2025-60212?
CVE-2025-60212 affects DesignThemes VEDA versions from n/a through 4.2.
4
Is CVE-2025-60212 exploitable remotely?
Yes, CVE-2025-60212 is exploitable remotely, making it critical to address immediately.
5
What are the potential impacts of CVE-2025-60212?
The potential impacts of CVE-2025-60212 include unauthorized access to sensitive data and remote command execution.