CVE-2025-60215: WordPress Kriya theme <= 3.4 - PHP Object Injection Vulnerability
Published Oct 22, 2025
·Updated
Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects Kriya: from n/a through <= 3.4.
Affected Software
1 affected component
DesignThemes Kriya<=3.4
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-60215?
The CVE-2025-60215 vulnerability has a high severity due to its potential for remote code execution through object injection.
2
How do I fix CVE-2025-60215?
To fix CVE-2025-60215, upgrade the Kriya theme to the latest version above 3.4 to mitigate the deserialization issues.
3
What software is affected by CVE-2025-60215?
CVE-2025-60215 affects DesignThemes Kriya theme versions from n/a to 3.4.
4
What is the nature of the vulnerability CVE-2025-60215?
CVE-2025-60215 is a deserialization of untrusted data vulnerability that allows for object injection.
5
Can CVE-2025-60215 be exploited remotely?
Yes, CVE-2025-60215 can be exploited remotely, allowing attackers to execute arbitrary code on the affected system.