PT-2026-21065 · Boldthemes · Travelicious

Published

2026-02-20

·

Updated

2026-02-22

·

CVE-2025-67997

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BoldThemes Travelicious versions prior to 1.6.7
Description The software contains a flaw due to deserialization of untrusted data, which allows for object injection. This could potentially allow an attacker to manipulate serialized data and execute arbitrary code.
Recommendations Update BoldThemes Travelicious to version 1.6.7 or later.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-67997

Affected Products

Travelicious