CVE-2025-69111
published 2026-06-17CVE-2025-69111: WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.39%
32.5th percentile
WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| themerex | reisen | n/a – 1.4.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
meREX Reisen Plugin up to 1.4.1 on WordPress deserialization (EUVD-2025-210253)
vuldb·2026-06-18
CVE-2025-69111 [CRITICAL] meREX Reisen Plugin up to 1.4.1 on WordPress deserialization (EUVD-2025-210253)
A vulnerability, which was classified as critical, has been found in meREX Reisen Plugin up to 1.4.1 on WordPress. Impacted is an unknown function. The manipulation leads to deserialization.
This vulnerability is documented as CVE-2025-69111. The attack can be initiated remotely. There is not any exploit available.
CVEList
WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability
cvelistv5·2026-06-17·CVSS 9.8
CVE-2025-69111 [CRITICAL] CWE-502 WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability
WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
GHSA
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
ghsa_unreviewed·2026-06-17
CVE-2025-69111 [CRITICAL] CWE-502 Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-17
Published