Description
Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects CouponXxL: from n/a through <= 3.0.0.
Published: 2025-06-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a deserialization flaw that allows an attacker to inject and execute arbitrary PHP objects. By supplying maliciously crafted serialized data to the CouponXxL theme, an attacker can trigger code execution with the privileges of the web application. This type of object injection can be leveraged to compromise the entire WordPress site, potentially leading to full system takeover. The weakness is categorized as CWE‑502, indicating that untrusted data is being deserialized without sufficient validation.

Affected Systems

WordPress installations that use the pebas CouponXxL theme version 3.0.0 or earlier are affected. Any site that has not yet upgraded beyond this version is vulnerable. The vulnerability affects the theme itself, not the core WordPress software or other plugins.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests that, based on current data, the probability of exploitation in the wild is low, yet the potential impact remains extremely high. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploit has been reported. The attack is most likely carried out remotely through crafted HTTP requests that include serialized data processed by the theme, meaning any exposed form or endpoint that accepts user input could be a potential entry point.

Generated by OpenCVE AI on April 30, 2026 at 10:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest CouponXxL theme update (≥3.0.1).
  • If immediate update is not feasible, deactivate the CouponXxL theme or switch to an alternative safe theme until a patch is applied.
  • Audit the theme code to remove or tightly validate any deserialization of user-supplied data; consider commenting out or disabling features that trigger serialization.

Generated by OpenCVE AI on April 30, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19296 Deserialization of Untrusted Data vulnerability in pebas CouponXxL allows Object Injection. This issue affects CouponXxL: from n/a through 3.0.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in pebas CouponXxL allows Object Injection. This issue affects CouponXxL: from n/a through 3.0.0. Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects CouponXxL: from n/a through <= 3.0.0.
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 27 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 12:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in pebas CouponXxL allows Object Injection. This issue affects CouponXxL: from n/a through 3.0.0.
Title WordPress CouponXxL theme <= 3.0.0 - PHP Object Injection Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:17.587Z

Reserved: 2025-06-19T10:02:25.009Z

Link: CVE-2025-52725

cve-icon Vulnrichment

Updated: 2025-06-27T13:08:59.880Z

cve-icon NVD

Status : Deferred

Published: 2025-06-27T12:15:39.950

Modified: 2026-04-23T15:32:05.447

Link: CVE-2025-52725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:30:34Z

Weaknesses