CVE-2025-60234: WordPress Single Property theme <= 2.8 - PHP Object Injection vulnerability
Published Oct 22, 2025
·Updated
Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Property: from n/a through <= 2.8.
Affected Software
2 affected components
DesignThemes Single Property<=2.8
WordPress Single Property<=2.8
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-60234?
CVE-2025-60234 is considered a high severity vulnerability due to its potential for object injection attacks.
2
How do I fix CVE-2025-60234?
To fix CVE-2025-60234, update the DesignThemes Single Property plugin to version 2.9 or later.
3
What types of attacks can CVE-2025-60234 enable?
CVE-2025-60234 can enable remote code execution and unauthorized access through object injection.
4
Which versions of Single Property are affected by CVE-2025-60234?
CVE-2025-60234 affects all versions of the Single Property plugin up to and including 2.8.
5
Is CVE-2025-60234 specific to any platform?
CVE-2025-60234 is specifically related to the DesignThemes Single Property plugin used within WordPress.