CVE-2025-60205
published 2026-06-17CVE-2025-60205: WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerability Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.53%
43.3th percentile
WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| themerex | themerex_addons | n/a – 2.36.1.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
meREX Addons Plugin up to 2.36.1.1 on WordPress deserialization
vuldb·2026-06-19
CVE-2025-60205 [CRITICAL] meREX Addons Plugin up to 2.36.1.1 on WordPress deserialization
A vulnerability was found in meREX Addons Plugin up to 2.36.1.1 on WordPress. It has been classified as critical. The impacted element is an unknown function. The manipulation leads to deserialization.
This vulnerability is listed as CVE-2025-60205. The attack may be initiated remotely. There is no available exploit.
GHSA
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
ghsa_unreviewed·2026-06-17
CVE-2025-60205 [CRITICAL] CWE-502 Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
CVEList
WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerability
cvelistv5·2026-06-17·CVSS 9.8
CVE-2025-60205 [CRITICAL] CWE-502 WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerability
WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-17
Published