CVE-2025-69294: WordPress PeakShops theme <= 1.5.9 - PHP Object Injection vulnerability
Published Feb 20, 2026
·Updated
Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a through <= 1.5.9.
Affected Software
1 affected component
FuelThemes PeakShops<=1.5.9
Event History
Feb 20, 2026
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-69294?
CVE-2025-69294 has a high severity rating of 8.8 on the CVSS scale.
2
How do I fix CVE-2025-69294?
To fix CVE-2025-69294, update the FuelThemes PeakShops theme to a version greater than 1.5.9.
3
What type of vulnerability is CVE-2025-69294?
CVE-2025-69294 is a PHP Object Injection vulnerability due to deserialization of untrusted data.
4
Which versions of PeakShops are affected by CVE-2025-69294?
CVE-2025-69294 affects PeakShops versions from n/a through 1.5.9.
5
What impact does CVE-2025-69294 have on my website?
CVE-2025-69294 can allow an attacker to exploit object injection, potentially compromising website data integrity and availability.