Deserialization of Untrusted Data in Teastudio.Pl WP Posts Carousel
CVE-2025-39358

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

What is CVE-2025-39358?

A deserialization vulnerability in the Teastudio.Pl WP Posts Carousel plugin allows for object injection due to the improper handling of untrusted data. This flaw potentially exposes the application to various attacks, enabling malicious users to manipulate serialized data and execute code or alter application behavior. Affected versions include WP Posts Carousel up to and including 1.3.12.

Affected Version(s)

WP Posts Carousel <= 1.3.12

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martino Spagnuolo - r3verii (Patchstack Alliance)
.
CVE-2025-39358 : Deserialization of Untrusted Data in Teastudio.Pl WP Posts Carousel