CVE-2025-60228: WordPress Knowledge Base theme <= 2.9 - PHP Object Injection vulnerability
Published Oct 22, 2025
·Updated
Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.
Affected Software
2 affected components
DesignThemes Knowledge Base<=2.9
WordPress Knowledge Base<=2.9
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-60228?
CVE-2025-60228 is classified as a critical vulnerability due to its potential for object injection attacks.
2
How do I fix CVE-2025-60228?
To fix CVE-2025-60228, you should update the DesignThemes Knowledge Base to version 2.10 or later.
3
What are the consequences of exploiting CVE-2025-60228?
Exploitation of CVE-2025-60228 may allow an attacker to execute arbitrary code on the server.
4
Which versions are affected by CVE-2025-60228?
CVE-2025-60228 affects all versions of DesignThemes Knowledge Base up to and including version 2.9.
5
What type of vulnerability is CVE-2025-60228?
CVE-2025-60228 is a deserialization of untrusted data vulnerability that allows for object injection.