CVE-2025-67997: WordPress Travelicious theme < 1.6.7 - PHP Object Injection vulnerability
Published Feb 20, 2026
·Updated
Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from n/a through < 1.6.7.
Affected Software
1 affected component
BoldThemes Travelicious<1.6.7
Event History
Feb 20, 2026
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-67997?
CVE-2025-67997 is classified as a high severity vulnerability due to potential remote code execution from PHP Object Injection.
2
How do I fix CVE-2025-67997?
To fix CVE-2025-67997, update the BoldThemes Travelicious theme to version 1.6.7 or later.
3
What does CVE-2025-67997 affect?
CVE-2025-67997 affects versions of the BoldThemes Travelicious theme prior to 1.6.7.
4
What type of vulnerability is CVE-2025-67997?
CVE-2025-67997 is a PHP Object Injection vulnerability caused by the deserialization of untrusted data.
5
Can CVE-2025-67997 lead to data compromise?
Yes, CVE-2025-67997 can lead to data compromise by allowing an attacker to execute arbitrary code.