PT-2026-21065 · Boldthemes · Travelicious
Published
2026-02-20
·
Updated
2026-02-22
·
CVE-2025-67997
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BoldThemes Travelicious versions prior to 1.6.7
Description
The software contains a flaw due to deserialization of untrusted data, which allows for object injection. This could potentially allow an attacker to manipulate serialized data and execute arbitrary code.
Recommendations
Update BoldThemes Travelicious to version 1.6.7 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Travelicious