CVE-2025-60214: WordPress Goldenblatt theme < 1.3.0 - PHP Object Injection vulnerability
Published Oct 22, 2025
·Updated
Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue affects Goldenblatt: from n/a through < 1.3.0.
Affected Software
1 affected component
BoldThemes Goldenblatt<1.3.0
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-60214?
CVE-2025-60214 is considered a critical severity vulnerability due to its potential for object injection and deserialization of untrusted data.
2
How do I fix CVE-2025-60214?
To fix CVE-2025-60214, upgrade BoldThemes Goldenblatt to version 1.2.2 or later.
3
What versions are affected by CVE-2025-60214?
CVE-2025-60214 affects BoldThemes Goldenblatt versions from n/a to 1.2.1.
4
What type of vulnerability is CVE-2025-60214?
CVE-2025-60214 is a deserialization of untrusted data vulnerability that allows for object injection.
5
Who is the vendor for CVE-2025-60214?
The vendor for CVE-2025-60214 is BoldThemes, which develops the Goldenblatt theme.