CVE-2025-69002: WordPress OneLife theme <= 3.9 - PHP Object Injection vulnerability
Published Jan 22, 2026
·Updated
Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through <= 3.9.
Affected Software
2 affected components
DesignThemes OneLife<=3.9
wordpress/onelife<=3.9
Event History
Jan 22, 2026
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-69002?
CVE-2025-69002 is rated as a high-severity vulnerability due to its potential for PHP Object Injection.
2
What versions of the OneLife theme are affected by CVE-2025-69002?
CVE-2025-69002 affects the OneLife theme versions up to and including 3.9.
3
How do I fix CVE-2025-69002?
To fix CVE-2025-69002, upgrade the OneLife theme to a version beyond 3.9.
4
What type of vulnerability is CVE-2025-69002?
CVE-2025-69002 is a PHP Object Injection vulnerability that allows deserialization of untrusted data.
5
Can CVE-2025-69002 affect my WordPress site?
Yes, CVE-2025-69002 can affect any WordPress site using the OneLife theme version 3.9 or earlier.