
🚨Critical - Creatify WordPress Theme PHP Object Injection (CVE-2025-60236) The EMV Creatify WordPress theme contains a deserialization of untrusted data flaw that allows PHP Object Injection. Attacker-controlled input reaches a PHP deserialization sink, letting an unauthenticated attacker inject crafted objects into the application. Paired with a usable gadget chain from the theme, an installed plugin, or WordPress core, this can escalate to full site compromise. The issue is remotely exploitable with no privileges or user interaction, and CISA assessed it as automatable with total technical impact. 👉Affected: Creatify <= 1.5.
Post summary
The article discloses a critical PHP Object Injection flaw in the Creatify WordPress theme that allows unauthenticated attackers to inject objects and, with a gadget chain, compromise the entire site, but no PoC, exploit code, patch, or evidence of live attacks are reported.
