Description
Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affects Medicare: from n/a through <= 2.1.0.
Published: 2025-05-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Medicare theme from BoldThemes contains a deserialization flaw that permits PHP object injection when it processes untrusted input. This weakness is identified as CWE-502 and can allow an attacker to execute arbitrary code on a vulnerable WordPress site. The vulnerability affects all releases of the Medicare theme up to and including version 2.1.0.

Affected Systems

WordPress installations that employ the BoldThemes Medicare theme version 2.1.0 or earlier are exposed. This includes any site that has not upgraded beyond the specified threshold.

Risk and Exploitability

The CVSS score of 9.8 signifies critical severity, and the EPSS score of less than 1% indicates a very low current exploitation likelihood. The issue is not listed in the CISA KEV catalog. The likely attack vector is the delivery of crafted serialized data to the theme, typically through specially constructed HTTP requests or user inputs processed by the theme. If an attacker succeeds in injecting a malicious object, they can gain remote code execution privileges on the affected WordPress installation.

Generated by OpenCVE AI on May 1, 2026 at 08:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade BoldThemes Medicare to version 2.2.0 or later, which removes the deserialization logic that permits object injection.
  • If a newer version is not immediately available, deactivate or remove the Medicare theme from the site to eliminate the vulnerable code paths.
  • Prior to applying a patch, restrict the sources of data that the theme accepts and enforce strict input validation for any serialized data, and monitor the site for suspicious unserialization activity.

Generated by OpenCVE AI on May 1, 2026 at 08:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19854 Deserialization of Untrusted Data vulnerability in BoldThemes Medicare allows Object Injection.This issue affects Medicare: from n/a through 2.1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in BoldThemes Medicare allows Object Injection.This issue affects Medicare: from n/a through 2.1.0. Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affects Medicare: from n/a through <= 2.1.0.
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 03 Jul 2025 11:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in BoldThemes Medicare allows Object Injection. This issue affects Medicare: from n/a through 2.1.0. Deserialization of Untrusted Data vulnerability in BoldThemes Medicare allows Object Injection.This issue affects Medicare: from n/a through 2.1.0.

Fri, 23 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 May 2025 13:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in BoldThemes Medicare allows Object Injection. This issue affects Medicare: from n/a through 2.1.0.
Title WordPress Medicare Theme <= 2.1.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:32.987Z

Reserved: 2025-04-16T06:24:15.128Z

Link: CVE-2025-39499

cve-icon Vulnrichment

Updated: 2025-05-23T13:29:43.156Z

cve-icon NVD

Status : Deferred

Published: 2025-05-23T13:15:31.360

Modified: 2026-04-23T15:29:40.703

Link: CVE-2025-39499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:15:12Z

Weaknesses