PT-2025-17191 · Bdthemes · Bdthemes Ultimate Store Kit Elementor Addons

Domiee13

·

Published

2025-04-17

·

Updated

2025-04-18

·

CVE-2025-39588

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bdthemes Ultimate Store Kit Elementor Addons versions n/a through 2.4.0
Description The issue is related to the deserialization of untrusted data, which allows object injection. This is a critical vulnerability that affects the specified versions of the software.
Recommendations For versions n/a through 2.4.0, update to a version later than 2.4.0 to resolve the issue. As a temporary workaround, consider restricting the deserialization of untrusted data to minimize the risk of object injection.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-39588

Affected Products

Bdthemes Ultimate Store Kit Elementor Addons