Description
Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows Object Injection.This issue affects Falang multilanguage: from n/a through <= 1.3.65.
Published: 2025-11-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Falang multilanguage plugin for WordPress contains a deserialization flaw that allows untrusted data to be processed without validation. This leads to object injection, giving an attacker the ability to create arbitrary PHP objects. The presence of an object injection vulnerability can enable remote code execution or other malicious actions that compromise confidentiality, integrity, or availability, depending on the attacker’s capabilities. The weakness is identified as a CWE‑502: Deserialization of untrusted data.

Affected Systems

All installations of the sbouey Falang multilanguage plugin from the initial release through version 1.3.65 are affected. Users running WordPress sites that have this plugin enabled and have not updated to a later version are at risk.

Risk and Exploitability

The flaw carries a high CVSS score of 8.8, indicating significant impact if successfully exploited. Its EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, with an attacker able to craft malicious payloads that the plugin processes during normal operation; the exact conditions are not explicitly described in the advisories, but the inference is that any user input processed by Falang could be manipulated.

Generated by OpenCVE AI on April 29, 2026 at 13:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Falang multilanguage plugin to version 1.3.66 or later.
  • If an upgrade cannot be performed immediately, restrict the plugin’s access to trusted administrative users and validate or sanitize all input that is deserialized by the plugin.
  • Enable logging and monitor for signs of unexpected deserialization activity or execution of unusual object methods.

Generated by OpenCVE AI on April 29, 2026 at 13:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Fri, 07 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 06 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows Object Injection.This issue affects Falang multilanguage: from n/a through <= 1.3.65.
Title WordPress Falang multilanguage Plugin <= 1.3.65 - PHP Object Injection Vulnerability
Weaknesses CWE-502
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:14:06.158Z

Reserved: 2025-09-03T09:02:47.358Z

Link: CVE-2025-58619

cve-icon Vulnrichment

Updated: 2025-11-07T16:10:33.227Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:15:59.400

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-58619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:00:12Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data