Deserialization Vulnerability in WP User Manager by WordPress
CVE-2025-60245

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-60245?

A deserialization vulnerability exists in the WP User Manager plugin for WordPress, specifically impacting versions up to 2.9.12. This flaw allows for object injection, potentially enabling an attacker to exploit the system by sending crafted input that can manipulate application behavior, leading to unauthorized actions or access. Maintaining updated software and implementing security best practices is crucial to mitigate such vulnerabilities.

Affected Version(s)

WP User Manager <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ngoc Quang Bach (maysbachs) | Patchstack Bug Bounty Program
.
CVE-2025-60245 : Deserialization Vulnerability in WP User Manager by WordPress