Object Injection Vulnerability in Dash by Meton
CVE-2025-31049

9.8CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 May 2025

What is CVE-2025-31049?

A deserialization of untrusted data vulnerability exists in Meton's Dash product, allowing attackers to exploit object injection weaknesses. This vulnerability can lead to unauthorized manipulation of application behavior, posing significant risks to data integrity and security. Users of Dash versions n/a through 1.3 are particularly vulnerable. It is crucial for users to implement security measures, including updating to the latest version and reviewing their security posture.

Affected Version(s)

Dash <= 1.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.