Deserialization of Untrusted Data Vulnerability in Cozmoslabs WP Webhooks
CVE-2025-66073

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 November 2025

What is CVE-2025-66073?

There is a deserialization of untrusted data vulnerability in Cozmoslabs' WP Webhooks plugin. This vulnerability allows for object injection, which may lead to unauthorized access or execution of arbitrary code. The affected versions extend from an undetermined point through 3.3.8, exposing users to potential security risks. Users are recommended to update to the latest version to mitigate these vulnerabilities and protect their WordPress installations.

Affected Version(s)

WP Webhooks <= n/a

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock | Patchstack Bug Bounty Program
.
CVE-2025-66073 : Deserialization of Untrusted Data Vulnerability in Cozmoslabs WP Webhooks