CVE-2025-53299
WordPress ThemeMakers Visual Content Composer Plugin <= 1.5.8 - PHP Object Injection Vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer allows Object Injection.This issue affects ThemeMakers Visual Content Composer: from n/a through <= 1.5.8.
| CWE | CWE-502 |
| Vendor | thememakers |
| Product | thememakers visual content composer |
| Published | Aug 20, 2025 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for thememakers thememakers visual content composer
Be the first to know when new unknown vulnerabilities affecting thememakers thememakers visual content composer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ThemeMakers / ThemeMakers Visual Content Composer
0 โค 1.5.8
References
Credits
Bonds | Patchstack Bug Bounty Program