Description
Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects Site Chat on Telegram: from n/a through <= 1.0.4.
Published: 2025-07-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a PHP object injection flaw that arises from deserialization of untrusted data within the Site Chat on Telegram plugin. When maliciously crafted serialized objects reach the plugin, they are instantiated, enabling an attacker to execute arbitrary code in the context of the WordPress site. This flaw effectively grants full control over the affected system, including potential data exfiltration, alteration, or further propagation of malware.

Affected Systems

The issue affects Guru Team's Site Chat on Telegram plugin, versions from the initial release through 1.0.4. WordPress sites that have installed any of these versions are vulnerable until the plugin is updated to a version beyond 1.0.4.

Risk and Exploitability

The CVSS base score is 9.8, indicating critical severity. The EPSS score is listed as < 1%, suggesting a low probability of exploitation at the moment, but the high severity means that any exploitation would have devastating consequences. Based on the description, it is inferred that the plugin processes serialized data sent via site requests, so the attack vector is likely remote and could involve crafted POST or GET requests that supply malicious serialized payloads. The flaw is not currently listed in CISA KEV, but organizations should not rely on this status. The risk remains high until a patched version is deployed or the plugin is removed.

Generated by OpenCVE AI on May 1, 2026 at 06:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Site Chat on Telegram to the latest version released after 1.0.4.
  • If upgrading is not immediately possible, disable or delete the plugin to eliminate the attack surface.
  • Verify that no object deserialization occurs by reviewing the plugin code or consulting the vendor for a formal fix and confirming no further unsanitized data is processed.

Generated by OpenCVE AI on May 1, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21608 Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram: from n/a through 1.0.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram: from n/a through 1.0.4. Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects Site Chat on Telegram: from n/a through <= 1.0.4.
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00038}


Wed, 16 Jul 2025 11:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram: from n/a through 1.0.4.
Title WordPress Site Chat on Telegram plugin <= 1.0.4 - PHP Object Injection Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:02.016Z

Reserved: 2025-03-26T09:22:08.301Z

Link: CVE-2025-30949

cve-icon Vulnrichment

Updated: 2025-07-16T13:47:23.326Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T12:15:24.987

Modified: 2026-04-23T15:27:23.140

Link: CVE-2025-30949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:00:06Z

Weaknesses