External risk intelligence

BoldThemes Addison Object Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-60216

The vulnerability affects a WordPress theme, which is a component of a web application. WordPress sites are commonly deployed as public-facing web services, making the theme's code and its associated functionality typically accessible via the public internet.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical security vulnerability impacting the Addison theme for BoldThemes. The issue, a deserialization of untrusted data flaw, could allow attackers to inject malicious code by exploiting how the theme processes certain data inputs. This could potentially lead to unauthorized access or control over affected systems if the theme is in use.

  • Data processing flaw in a website theme.
  • Enables malicious code injection via data input.
  • Assess relevance and potential exposure of the theme.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted data to a vulnerable installation of the Addison theme, without needing any special access or authentication. This data would then be deserialized, leading to the injection of arbitrary objects into the application's memory, which could then be executed.

  • No authentication required.
  • Sending untrusted serialized data.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow an attacker to inject arbitrary PHP objects into the system through the Addison theme. This could potentially lead to the execution of malicious code, affecting the integrity and availability of the application and its underlying system.

  • Arbitrary PHP object injection.
  • Via untrusted data during deserialization.
  • Malicious code execution on the server.

Operational Fix

Recommended remediation, mitigation, and detection steps

This deserialization vulnerability in BoldThemes Addison requires immediate attention from the platform or application owner responsible for the WordPress site. The first practical step is to identify all instances of the affected theme, assess their exposure to the internet, and determine their criticality to business operations. Once identified, the accountable owner should be engaged to plan and execute remediation.

  • Application or platform owners should manage this issue.
  • Verify theme installation and public accessibility first.
  • Plan remediation, prioritizing critical and exposed instances.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the BoldThemes Addison product?

Addison is a WordPress theme developed by BoldThemes. WordPress themes control the visual design, layout, and some functional features of a website. When a theme is installed on a WordPress site, it executes server-side code to render pages for visitors.

What does CWE-502 mean for CVE-2025-60216?

CWE-502 refers to Deserialization of Untrusted Data. This happens when an application takes data from an outside source and converts it back into an object without verifying its contents. In this CVE, the Addison theme may trust this incoming data too much, allowing an attacker to inject unauthorized objects that the server then processes.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending specifically crafted, malicious data to the Addison theme. This does not require the attacker to have an account or any prior access to the website. Simply visiting the site or interacting with a component that processes this untrusted input is enough. The bug is not triggered by standard, legitimate user interactions.

Why is this CVE relevant to my web server?

According to Halo Surface Signal, this vulnerability is relevant because WordPress themes are typically part of public-facing web services. If your site uses the Addison theme and is accessible via the internet, it is inherently reachable by external actors. This makes internal-only systems less of a priority than those directly exposed to web traffic.

How do I respond to this Addison theme issue?

Start by auditing your environment to locate every website using the Addison theme. Once you have an inventory, determine which sites are internet-facing to prioritize them. Coordinate with your web administrators to review the specific theme configuration and prepare to apply updates or implement security controls to mitigate the risk of object injection.

References