CVE-2025-48289: Ancorathemes Kids Planet
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issue affects Kids Planet: from n/a through <= 2.2.14.
Affected products
- Ancorathemes Kids Planet: up to and including 2.2.14
Published 2025-05-23. Last modified 2026-06-17.