CVE-2025-69301: WordPress PhotoMe theme <= 5.6.11 - PHP Object Injection vulnerability
Published Feb 20, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <= 5.6.11.
Affected Software
2 affected components
ThemeGoods PhotoMe<=5.6.11
WordPress PhotoMe<=5.6.11
Event History
Feb 20, 2026
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-69301?
CVE-2025-69301 is considered a high severity vulnerability due to its potential for PHP Object Injection.
2
How do I fix CVE-2025-69301?
To fix CVE-2025-69301, you should update the ThemeGoods PhotoMe theme to a version newer than 5.6.11.
3
Who is affected by CVE-2025-69301?
CVE-2025-69301 affects users of the ThemeGoods PhotoMe theme on WordPress versions up to and including 5.6.11.
4
What type of vulnerability is CVE-2025-69301?
CVE-2025-69301 is a PHP Object Injection vulnerability that allows attackers to perform deserialization of untrusted data.
5
When was CVE-2025-69301 disclosed?
The disclosure date for CVE-2025-69301 is not specified, but it affects versions of the PhotoMe theme released before 5.6.12.