Deserialization of Untrusted Data in emarket-design Employee Spotlight Plugin
CVE-2025-53583
What is CVE-2025-53583?
The emarket-design Employee Spotlight plugin for WordPress is susceptible to a deserialization of untrusted data vulnerability, which can result in object injection issues. This security concern allows an attacker to manipulate the deserialization process, potentially leading to arbitrary code execution within the context of the application. Users running versions from n/a through 5.1.1 are particularly at risk, making it essential to ensure that appropriate security measures are taken to mitigate potential threats and protect user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Employee Spotlight <= 5.1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved