Deserialization of Untrusted Data in emarket-design Employee Spotlight Plugin
CVE-2025-53583

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 August 2025

What is CVE-2025-53583?

The emarket-design Employee Spotlight plugin for WordPress is susceptible to a deserialization of untrusted data vulnerability, which can result in object injection issues. This security concern allows an attacker to manipulate the deserialization process, potentially leading to arbitrary code execution within the context of the application. Users running versions from n/a through 5.1.1 are particularly at risk, making it essential to ensure that appropriate security measures are taken to mitigate potential threats and protect user data.

Affected Version(s)

Employee Spotlight <= 5.1.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martino Spagnuolo (r3verii) (Patchstack Alliance)
.
CVE-2025-53583 : Deserialization of Untrusted Data in emarket-design Employee Spotlight Plugin