CVE-2025-68899: WordPress Vivagh theme <= 2.4 - PHP Object Injection vulnerability
Published Jan 22, 2026
·Updated
Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= 2.4.
Affected Software
1 affected component
DesignThemes Vivagh<=2.4
Event History
Jan 22, 2026
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-68899?
The severity of CVE-2025-68899 is considered high due to the risks associated with PHP Object Injection vulnerabilities.
2
How do I fix CVE-2025-68899?
To fix CVE-2025-68899, upgrade the Vivagh theme to version 2.5 or later.
3
What software is affected by CVE-2025-68899?
CVE-2025-68899 affects the DesignThemes Vivagh theme versions up to and including 2.4.
4
What type of vulnerability is CVE-2025-68899?
CVE-2025-68899 is a PHP Object Injection vulnerability involving deserialization of untrusted data.
5
Can CVE-2025-68899 be exploited remotely?
Yes, CVE-2025-68899 can be exploited remotely, allowing unauthorized access or control over the affected application.