Object Injection Vulnerability in Brent Jett Assistant Plugin
CVE-2025-26885

7.2HIGH

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
3 March 2025

Summary

A notable deserialization vulnerability exists in the Brent Jett Assistant plugin for WordPress, which allows for object injection through untrusted data. This vulnerability affects versions from n/a to 1.5.1 of the Assistant plugin, potentially enabling attackers to manipulate objects in the system. Proper security measures and updates are essential to mitigate risks associated with this security flaw.

Affected Version(s)

Assistant <= 1.5.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock (Patchstack Alliance)
.