Deserialization Vulnerability in WP User Manager by WordPress
CVE-2025-60245
9.8CRITICAL
What is CVE-2025-60245?
A deserialization vulnerability exists in the WP User Manager plugin for WordPress, specifically impacting versions up to 2.9.12. This flaw allows for object injection, potentially enabling an attacker to exploit the system by sending crafted input that can manipulate application behavior, leading to unauthorized actions or access. Maintaining updated software and implementing security best practices is crucial to mitigate such vulnerabilities.
Affected Version(s)
WP User Manager <= n/a
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Ngoc Quang Bach (maysbachs) | Patchstack Bug Bounty Program