CVE-2025-30889: WordPress Testimonial Slider plugin <= 2.0.13 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.This issue affects Testimonial Slider: from n/a through <= 2.0.13.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30889?
The severity of CVE-2025-30889 is considered to be medium due to its potential for object injection attacks.
How do I fix CVE-2025-30889?
To fix CVE-2025-30889, you should update the PickPlugins Testimonial Slider plugin to version 2.0.14 or later.
What impact does CVE-2025-30889 have on affected systems?
CVE-2025-30889 could allow an attacker to exploit untrusted data deserialization, leading to possible remote code execution.
Which versions of Testimonial Slider are affected by CVE-2025-30889?
CVE-2025-30889 affects all versions of PickPlugins Testimonial Slider from the earliest release up to and including version 2.0.13.
Is CVE-2025-30889 specific to any platform?
Yes, CVE-2025-30889 is specifically related to the PickPlugins Testimonial Slider used in WordPress.