Object Injection Vulnerability in Membership Software by WishList
CVE-2026-25445
8.8HIGH
What is CVE-2026-25445?
A deserialization of untrusted data vulnerability exists within the Membership Software WishList Member X. This flaw allows malicious actors to perform object injection, potentially compromising user data and system integrity. The issue impacts versions from n/a to 3.29.0, making it critical for users running affected versions to address this security threat promptly.
Affected Version(s)
WishList Member X 0 <= 3.29.0