PT-2025-43316 · Boldthemes · Addison

Bonds

·

Published

2025-10-22

·

Updated

2025-10-22

·

CVE-2025-60216

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BoldThemes Addison versions through 1.4.2
Description A flaw exists in BoldThemes Addison that allows for object injection due to deserialization of untrusted data. This issue could potentially allow an attacker to compromise the system.
Recommendations Update BoldThemes Addison to a version newer than 1.4.2.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60216

Affected Products

Addison