CVE-2025-69405: WordPress Lorem Ipsum | Books & Media Store theme <= 1.2.11 - PHP Object Injection vulnerability
Published Feb 20, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.11.
Affected Software
1 affected component
ThemeREX Lorem Ipsum | Books & Media Store<=1.2.11
Event History
Feb 20, 2026
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-69405?
CVE-2025-69405 is classified as a Medium severity vulnerability due to the potential for PHP Object Injection.
2
How do I fix CVE-2025-69405?
To fix CVE-2025-69405, update the ThemeREX Lorem Ipsum | Books & Media Store theme to version 1.2.7 or later.
3
What kind of vulnerability is CVE-2025-69405?
CVE-2025-69405 is a PHP Object Injection vulnerability caused by deserialization of untrusted data.
4
Which versions of the Lorem Ipsum | Books & Media Store are affected by CVE-2025-69405?
CVE-2025-69405 affects ThemeREX Lorem Ipsum | Books & Media Store versions up to and including 1.2.6.
5
Can CVE-2025-69405 lead to remote code execution?
Yes, CVE-2025-69405 could potentially allow attackers to execute arbitrary code on affected systems.