Description
Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issue affects Kids Planet: from n/a through <= 2.2.14.
Published: 2025-05-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Deserialization of Untrusted Data flaw in the AncoraThemes Kids Planet WordPress theme permits PHP Object Injection. When the theme processes serialized input, an attacker can craft objects that, due to insufficient validation, trigger execution of arbitrary PHP code in the context of the WordPress site. This weakness is classified as CWE-502 and carries a CVSS score of 9.8, indicating a critical potential for compromising site integrity and confidentiality.

Affected Systems

WordPress installations that use AncoraThemes Kids Planet version 2.2.14 or earlier are affected. The flaw exists in all releases from the first version through 2.2.14, regardless of other plugins or configurations.

Risk and Exploitability

The EPSS score is below 1%, suggesting that exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. Because the issue relies on deserialization of untrusted data, the attack vector is likely remote – an attacker would need to supply malicious serialized content via a public interface that the theme accepts. Based on the description, it is inferred that such a transmission point could be a public form, an API endpoint, or any other user‑supplied input processed by the theme, but the CVE does not specify a concrete channel. The high CVSS score underscores the severe impact should exploitation succeed, but actual risk depends on the presence of a suitable deserialization entry point.

Generated by OpenCVE AI on April 30, 2026 at 19:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Kids Planet theme to a patched version newer than 2.2.14.
  • If an upgrade cannot be performed, deactivate or remove the theme to eliminate the attack surface.
  • Perform a security review of the WordPress installation to locate other deserialization points and strengthen input validation.

Generated by OpenCVE AI on April 30, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28203 Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet allows Object Injection. This issue affects Kids Planet: from n/a through 2.2.14.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet allows Object Injection. This issue affects Kids Planet: from n/a through 2.2.14. Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issue affects Kids Planet: from n/a through <= 2.2.14.
Title WordPress Kids Planet <= 2.2.14 - PHP Object Injection Vulnerability WordPress Kids Planet theme <= 2.2.14 - PHP Object Injection Vulnerability
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 23 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 May 2025 13:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet allows Object Injection. This issue affects Kids Planet: from n/a through 2.2.14.
Title WordPress Kids Planet <= 2.2.14 - PHP Object Injection Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:55.228Z

Reserved: 2025-05-19T14:13:30.917Z

Link: CVE-2025-48289

cve-icon Vulnrichment

Updated: 2025-05-23T15:26:10.656Z

cve-icon NVD

Status : Deferred

Published: 2025-05-23T13:15:44.897

Modified: 2026-04-23T15:31:02.403

Link: CVE-2025-48289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T19:30:26Z

Weaknesses