Deserialization of Untrusted Data in emarket-design Employee Spotlight Plugin
CVE-2025-53583
8.1HIGH
What is CVE-2025-53583?
The emarket-design Employee Spotlight plugin for WordPress is susceptible to a deserialization of untrusted data vulnerability, which can result in object injection issues. This security concern allows an attacker to manipulate the deserialization process, potentially leading to arbitrary code execution within the context of the application. Users running versions from n/a through 5.1.1 are particularly at risk, making it essential to ensure that appropriate security measures are taken to mitigate potential threats and protect user data.
Affected Version(s)
Employee Spotlight <= 5.1.1