Description
Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object Injection.This issue affects EmpikPlace for Woocommerce: from n/a through <= 1.4.3.
Published: 2025-04-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a deserialization of untrusted data that permits PHP Object Injection, allowing an attacker to manipulate object state or execution flow. This flaw directly maps to CWE-502 and can potentially lead to arbitrary code execution, data corruption, or compromise of the WordPress site host. No additional attack vectors are described, but the nature of object injection suggests remote exploitation through crafted input passed to the plugin.

Affected Systems

The issue affects the EmpikPlace for Woocommerce plugin from its initial release through version 1.4.3. Any WordPress site using this plugin within that version range is susceptible.

Risk and Exploitability

The CVSS score of 9.8 classifies the issue as critical. While the EPSS score is reported as less than 1 percent, indicating a low current probability of exploitation, the severity warrants immediate attention. The vulnerability is not listed in CISA KEV, but the high score and potential for remote code execution mean that attackers could exploit this flaw once the necessary conditions—such as a WordPress site with the vulnerable plugin—are met. The likely attack path involves submitting specially crafted input that is unserialized by the plugin, leading to object instantiation that can be leveraged to execute arbitrary code.

Generated by OpenCVE AI on April 30, 2026 at 23:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update EmpikPlace for Woocommerce to version 1.4.4 or later to remove the deserialization vulnerability
  • Disable or delete the plugin if it is not required for site functionality
  • Review site configuration to restrict deserialization of untrusted data and apply general PHP security hardening measures

Generated by OpenCVE AI on April 30, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10761 Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce allows Object Injection. This issue affects EmpikPlace for Woocommerce: from n/a through 1.4.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce allows Object Injection. This issue affects EmpikPlace for Woocommerce: from n/a through 1.4.2. Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object Injection.This issue affects EmpikPlace for Woocommerce: from n/a through <= 1.4.3.
Title WordPress EmpikPlace for Woocommerce Plugin <= 1.4.2 - PHP Object Injection vulnerability WordPress EmpikPlace for Woocommerce Plugin <= 1.4.3 - PHP Object Injection vulnerability
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 11 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Apr 2025 09:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce allows Object Injection. This issue affects EmpikPlace for Woocommerce: from n/a through 1.4.2.
Title WordPress EmpikPlace for Woocommerce Plugin <= 1.4.2 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:24.337Z

Reserved: 2025-04-09T11:20:09.347Z

Link: CVE-2025-32568

cve-icon Vulnrichment

Updated: 2025-04-11T13:31:25.922Z

cve-icon NVD

Status : Deferred

Published: 2025-04-11T09:15:28.447

Modified: 2026-04-23T15:29:07.543

Link: CVE-2025-32568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:15:05Z

Weaknesses