CVE-2025-24601: WordPress FundPress plugin <= 2.0.6 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in ThimPress FundPress fundpress allows Object Injection.This issue affects FundPress: from n/a through <= 2.0.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24601?
CVE-2025-24601 is classified as a high severity vulnerability due to the potential for object injection through deserialization of untrusted data.
How do I fix CVE-2025-24601?
To mitigate CVE-2025-24601, it is recommended to update ThimPress FundPress to the latest version beyond 2.0.6 which addresses this vulnerability.
What versions of FundPress are affected by CVE-2025-24601?
CVE-2025-24601 affects all versions of FundPress from the initial release up to and including version 2.0.6.
What types of attacks can be executed due to CVE-2025-24601?
CVE-2025-24601 can allow an attacker to inject malicious objects, potentially leading to remote code execution or data compromise.
Is CVE-2025-24601 exploitable without authentication?
Yes, CVE-2025-24601 can be exploited without authentication, making it particularly dangerous for public-facing sites.