First published: Fri Mar 28 2025(Updated: )
Deserialization of Untrusted Data vulnerability in NotFound PHP/MySQL CPU performance statistics allows Object Injection. This issue affects PHP/MySQL CPU performance statistics: from n/a through 1.2.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound NotFound PHP/MySQL CPU performance statistics | >=1.2.1 | |
WordPress PHP/MySQL CPU performance statistics Plugin | <=1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-22526 is classified as critical due to its potential for object injection via deserialization of untrusted data.
To fix CVE-2025-22526, update the NotFound PHP/MySQL CPU performance statistics plugin to version 1.2.1 or later.
CVE-2025-22526 affects NotFound PHP/MySQL CPU performance statistics versions from n/a through 1.2.1 and the WordPress PHP/MySQL CPU performance statistics plugin up to version 1.2.1.
CVE-2025-22526 is a deserialization of untrusted data vulnerability that can lead to object injection.
As of now, there are no publicly disclosed exploits for CVE-2025-22526, but it is recommended to apply fixes as a precaution.