CVE-2025-30773: WordPress TranslatePress plugin <= 2.9.6 - PHP Object Injection Vulnerability
Published Mar 27, 2025
·Updated
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.
Affected Software
1 affected component
Cozmoslabs TranslatePress<=2.9.6
Remediation
Information
Update the WordPress TranslatePress plugin to the latest available version (at least 2.9.7).
Event History
Mar 27, 2025
CVE Published
via MITRE·10:54 AM
Data Sourced
via MITRE·10:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-30773?
CVE-2025-30773 has a high severity due to the potential for object injection and deserialization of untrusted data.
2
How do I fix CVE-2025-30773?
To fix CVE-2025-30773, upgrade TranslatePress to version 2.9.7 or later.
3
Which versions of TranslatePress are affected by CVE-2025-30773?
CVE-2025-30773 affects TranslatePress versions from n/a to 2.9.6.
4
What type of vulnerability is CVE-2025-30773 classified as?
CVE-2025-30773 is classified as a deserialization of untrusted data vulnerability.
5
Is CVE-2025-30773 specific to certain platforms or can it affect others?
CVE-2025-30773 specifically affects the Cozmoslabs and WordPress versions of TranslatePress.