Description
Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1.
Published: 2025-05-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Business plugin for WordPress contains a deserialization bug that allows attackers to inject malicious PHP objects into the application. The vulnerability originates from unvalidated, user‑supplied serialized data being processed by the plugin. Because the plugin deserializes data without rejecting forged input, an attacker can craft a payload that instantiates arbitrary objects, potentially leading to remote code execution or privilege escalation within the WordPress site. This flaw is categorized as CWE‑502, describing deserialization of untrusted data.

Affected Systems

Affected systems are WordPress sites running The Business plugin versions from the initial release up through version 1.6.1. The vendor, themeton, has acknowledged that the issue exists in all releases before 1.6.2. Site administrators must determine whether they are using a vulnerable version and plan to upgrade accordingly.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, and the EPSS score of less than 1 percent shows that currently there is very low anecdotal evidence of exploitation, but the risk remains high due to the critical nature of the flaw and its potential for remote code execution. The vulnerability is not listed in the CISA KEV catalog, but the absence of a KEV status does not reduce the urgency. The likely attack vector is inferred to be through any interface that accepts serialized input from users, such as REST endpoints or plugin configuration pages. No publicly disclosed exploit code is available, but the nature of the flaw makes it straightforward for a determined attacker to construct a payload.

Generated by OpenCVE AI on April 30, 2026 at 18:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update The Business plugin to the latest version that includes the deserialization fix issued by themeton.
  • If the plugin cannot be updated immediately, remove or disable The Business from the WordPress installation to prevent exploitation until a patch is applied.
  • As a precautionary hardening measure, restrict or disable WordPress’ ability to unserialize data from untrusted sources by blocking or sanitizing relevant endpoints, or by installing a security plugin that enforces strict validation of serialized input.

Generated by OpenCVE AI on April 30, 2026 at 18:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-27805 Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1.
History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in themeton The Business nrgbusiness allows Object Injection.This issue affects The Business: from n/a through <= 1.6.1. Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1.
Title WordPress The Business theme <= 1.6.1 - PHP Object Injection Vulnerability WordPress The Business <= 1.6.1 - PHP Object Injection Vulnerability
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1. Deserialization of Untrusted Data vulnerability in themeton The Business nrgbusiness allows Object Injection.This issue affects The Business: from n/a through <= 1.6.1.
Title WordPress The Business <= 1.6.1 - PHP Object Injection Vulnerability WordPress The Business theme <= 1.6.1 - PHP Object Injection Vulnerability
References

Fri, 23 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 May 2025 13:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1.
Title WordPress The Business <= 1.6.1 - PHP Object Injection Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:06.910Z

Reserved: 2025-03-28T11:00:15.484Z

Link: CVE-2025-31430

cve-icon Vulnrichment

Updated: 2025-05-23T13:22:38.598Z

cve-icon NVD

Status : Deferred

Published: 2025-05-23T13:15:27.183

Modified: 2026-04-28T19:31:03.140

Link: CVE-2025-31430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T19:00:14Z

Weaknesses