Description
Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affects WPFunnels: from n/a through <= 3.5.18.
Published: 2025-05-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a deserialization flaw that allows an attacker to inject a PHP object into the WPFunnels plugin along with malicious serialized data. When the plugin unserializes that data, it can instantiate the attacker‑controlled object, which may trigger arbitrary code execution or modify system state. The weakness is classified as CWE‑502, a deserialization of untrusted data issue that can lead to remote code execution. The impact is that an unauthenticated attacker could run arbitrary code on the WordPress site, compromising confidentiality, integrity, and availability. Based on the description, it is inferred that the plugin deserializes input data received via HTTP requests, making the remote attack vector possible.

Affected Systems

The vulnerability affects the WPFunnels plugin for WordPress, versions up to and including 3.5.18. No specific WordPress core or other product version is listed; the issue exists across all versions from the earliest documented through 3.5.18.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, but the EPSS score of less than 1 % suggests that exploitation attempts are currently rare or have low probability. The vulnerability is not listed in the CISA KEV catalog. Because the plugin accepts serialized payloads from external clients, an attacker can craft a malicious request to trigger the object injection, assuming no other defenses (such as input sanitization) are present. The risk is high for any site running a vulnerable version of WPFunnels and could result in full compromise of the site.

Generated by OpenCVE AI on April 30, 2026 at 12:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WPFunnels plugin to the latest version (3.5.19 or later) to apply the vendor fix for the deserialization issue.
  • If an immediate upgrade is not possible, remove or disable the WPFunnels plugin until the patch is installed.
  • Ensure that the WordPress installation and all other plugins are kept up to date, as patching one component does not protect against mitigations that rely on other software checks.

Generated by OpenCVE AI on April 30, 2026 at 12:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28091 Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels allows Object Injection. This issue affects WPFunnels: from n/a through 3.5.18.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels allows Object Injection. This issue affects WPFunnels: from n/a through 3.5.18. Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affects WPFunnels: from n/a through <= 3.5.18.
Title WordPress WPFunnels <= 3.5.18 - PHP Object Injection Vulnerability WordPress WPFunnels plugin <= 3.5.18 - PHP Object Injection Vulnerability
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 23 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 May 2025 13:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels allows Object Injection. This issue affects WPFunnels: from n/a through 3.5.18.
Title WordPress WPFunnels <= 3.5.18 - PHP Object Injection Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:44.125Z

Reserved: 2025-05-07T09:39:46.952Z

Link: CVE-2025-47530

cve-icon Vulnrichment

Updated: 2025-05-23T15:19:48.174Z

cve-icon NVD

Status : Deferred

Published: 2025-05-23T13:15:38.897

Modified: 2026-04-23T15:30:25.410

Link: CVE-2025-47530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T12:30:16Z

Weaknesses