Object Injection Vulnerability in Brent Jett Assistant Plugin
CVE-2025-26885
7.2HIGH
Summary
A notable deserialization vulnerability exists in the Brent Jett Assistant plugin for WordPress, which allows for object injection through untrusted data. This vulnerability affects versions from n/a to 1.5.1 of the Assistant plugin, potentially enabling attackers to manipulate objects in the system. Proper security measures and updates are essential to mitigate risks associated with this security flaw.
Affected Version(s)
Assistant <= 1.5.1
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Phat RiO - BlueRock (Patchstack Alliance)