CVE-2025-60236Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-17: 1Technical Details · 2026-06-17: 106-17
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Creatify WordPress Theme PHP Object Injection (CVE-2025-60236) The EMV Creatify WordPress theme contains a deserialization of untrusted data flaw that allows PHP Object Injection. Attacker-controlled input reaches a PHP deserialization sink, letting an unauthenticated attacker inject crafted objects into the application. Paired with a usable gadget chain from the theme, an installed plugin, or WordPress core, this can escalate to full site compromise. The issue is remotely exploitable with no privileges or user interaction, and CISA assessed it as automatable with total technical impact. 👉Affected: Creatify <= 1.5.

    Post summary

    The article discloses a critical PHP Object Injection flaw in the Creatify WordPress theme that allows unauthenticated attackers to inject objects and, with a gadget chain, compromise the entire site, but no PoC, exploit code, patch, or evidence of live attacks are reported.

    0000052
    217 followersView on X

Explore more