Description
Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1.
Published: 2025-03-03
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Deserialization of untrusted data in Beaver Builder WordPress Assistant plugin allows an attacker to inject PHP objects, potentially enabling arbitrary code execution or other malicious actions. The vulnerability arises when the plugin deserializes client‑supplied input without proper validation, giving an adversary control over object properties and execution flow. This flaw could compromise the confidentiality, integrity, and availability of the affected WordPress site if successfully exploited.

Affected Systems

All installations of the WordPress Assistant plugin from Beaver Builder with version 1.5.1 or earlier are affected. The vulnerability applies to every site using the plugin regardless of the WordPress core version, as the flaw resides in the plugin code itself.

Risk and Exploitability

The CVSS base score of 7.2 indicates a high severity, while the EPSS score of less than 1% shows that exploitation is currently considered unlikely. The flaw is not listed in the CISA KEV catalog, meaning no known active exploits have been reported. Based on the description, it is inferred that an attacker would need to supply crafted input that triggers the vulnerable deserialization logic, which could be achieved via a special HTTP request or through an authenticated user’s request if the plugin accepts user data. The likely attack vector is the injection of malicious serialized data into the plugin's inputs. The lack of high EPSS suggests that the threat remains moderate until an exploit becomes available.

Generated by OpenCVE AI on May 2, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WordPress Assistant plugin to a version newer than 1.5.1 that removes the vulnerable deserialization logic.
  • If an immediate update is not feasible, disable the plugin or restrict its use to trusted administrators only to prevent unauthenticated input from triggering the flaw.
  • Apply broader PHP hardening measures such as disabling unused serialization functions or enforcing strict type checks to mitigate similar deserialization weaknesses.

Generated by OpenCVE AI on May 2, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5613 Deserialization of Untrusted Data vulnerability in Brent Jett Assistant allows Object Injection. This issue affects Assistant: from n/a through 1.5.1.
History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Brent Jett Assistant allows Object Injection. This issue affects Assistant: from n/a through 1.5.1. Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1.
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Brent Jett Assistant allows Object Injection. This issue affects Assistant: from n/a through 1.5.1.
Title WordPress Assistant Plugin <= 1.5.1 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:54.699Z

Reserved: 2025-02-17T11:50:22.450Z

Link: CVE-2025-26885

cve-icon Vulnrichment

Updated: 2025-03-03T14:26:47.954Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:56.360

Modified: 2026-04-29T10:16:42.637

Link: CVE-2025-26885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:45:33Z

Weaknesses