Description
Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affects ADFO: from n/a through <= 1.9.1.
Published: 2025-02-24
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ADFO admin‑form plugin accepts serialized data that is not properly validated, allowing attackers to craft serialized objects that are deserialized by the application. This flaw permits object injection, and the potential for remote code execution is inferred from the nature of object injection, though the CVE description does not explicitly state a confirmed RCE. The impact could include execution of arbitrary code, privilege escalation, or other malicious actions that compromise the confidentiality, integrity, or availability of a WordPress site.

Affected Systems

The vulnerability exists in the giuliopanda ADFO WordPress plugin versions up through 1.9.1. Any WordPress installation that has this plugin installed and has not been upgraded to a later version is affected.

Risk and Exploitability

The measured severity is a CVSS score of 7.2, indicating a high likelihood of serious impact. The EPSS score of less than 1 % suggests that, as of now, the probability of exploitation is low, and the flaw is not currently listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring an attacker to supply crafted input to the plugin’s deserialization logic, which is commonly achieved via a specially crafted HTTP request or API payload.

Generated by OpenCVE AI on May 2, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ADFO plugin to the newest version that addresses the deserialization flaw; if an update is not available, uninstall or disable the plugin immediately.
  • Apply a security plugin or custom code that blocks PHP unserialize for user‑supplied data in the affected plugin; this may mitigate the risk until a formal patch is released.
  • Monitor the vendor’s announcements and the WordPress security community for a patch or workaround, and apply the fix as soon as it becomes available.

Generated by OpenCVE AI on May 2, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4330 Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This issue affects ADFO: from n/a through 1.9.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This issue affects ADFO: from n/a through 1.9.1. Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affects ADFO: from n/a through <= 1.9.1.
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Mon, 24 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This issue affects ADFO: from n/a through 1.9.1.
Title WordPress ADFO plugin <= 1.9.1 - Deserialization of untrusted data vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:47.509Z

Reserved: 2025-02-21T16:45:27.526Z

Link: CVE-2025-27300

cve-icon Vulnrichment

Updated: 2025-02-24T15:56:12.539Z

cve-icon NVD

Status : Deferred

Published: 2025-02-24T15:15:15.853

Modified: 2026-04-23T15:26:19.600

Link: CVE-2025-27300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:30:16Z

Weaknesses