CVE-2025-32572
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 17, 2025
CWE ID 502
Summary
CVE-2025-32572 is a deserialization vulnerability affecting Climax Themes Kata Plus, specifically versions from n/a to 1.5.2. Hackers can exploit this issue, identified as a deserialization of untrusted data, to perform object injection. This weakness allows malicious code execution, potentially compromising affected systems and data. Organizations using this theme are advised to apply the necessary patches or updates promptly to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.