What is CVE-2025-15672?
An unsafe deserialization vulnerability was found in the ChamaWP WordPress plugin before version 1.0.13, allowing unauthenticated attackers to inject arbitrary PHP objects due to improper input validation. This could lead to remote code execution (RCE) if a suitable gadget chain is present; users must update to version 1.0.13 or later immediately.
Azərbaycanca: ChamaWP WordPress plaginində (1.0.13-dən əvvəlki versiyalarda) autentifikasiya olunmamış istifadəçilərə PHP obyektləri daxil etməyə imkan verən təhlükəli deserializasiya zəifliyi aşkarlanıb. Bu, uyğun gadget chain mövcud olduqda uzaqdan kod icrasına (RCE) səbəb ola bilər; istifadəçilər dərhal 1.0.13 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
What is the CVE-2025-15672 vulnerability in the ChamaWP plugin?
CVE-2025-15672 is an unsafe deserialization vulnerability found in the ChamaWP WordPress plugin before version 1.0.13, allowing unauthenticated attackers to inject arbitrary PHP objects.
How can I fix the CVE-2025-15672 vulnerability?
To protect against CVE-2025-15672, you must immediately update the ChamaWP plugin to version 1.0.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.