Deserialization of Untrusted Data in Teastudio.Pl WP Posts Carousel
CVE-2025-39358
8.8HIGH
What is CVE-2025-39358?
A deserialization vulnerability in the Teastudio.Pl WP Posts Carousel plugin allows for object injection due to the improper handling of untrusted data. This flaw potentially exposes the application to various attacks, enabling malicious users to manipulate serialized data and execute code or alter application behavior. Affected versions include WP Posts Carousel up to and including 1.3.12.
Affected Version(s)
WP Posts Carousel <= 1.3.12