CVE@CVEnewGeneral
The text notes CVE-2025-60237, a deserialization‑based object injection flaw in Themeton Finag affecting versions up to 1.5.0, but provides no evidence of active exploitation, PoC, or patch details.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE-2025-60237, detailing an unauthenticated PHP object injection in a WordPress theme with a high CVSS score and a potential RCE chain, but offers no patches, exploits, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2025-60237 is disclosed as a Finag Object Injection vulnerability arising from untrusted data deserialization, with no reported exploitation or mitigation details presented.
CVEFind.com@CveFindComDisclosure
The post announces a critical deserialization vulnerability (CVE‑2025‑60237) in Themeton Finag, detailing the type of attack and affected versions, but provides no evidence of exploitation, PoC, or patch availability.