CVE-2025-30892: WordPress WpTravelly Plugin <= 1.8.7 - PHP Object Injection vulnerability
Published Apr 1, 2025
·Updated
Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injection.This issue affects WpTravelly: from n/a through <= 1.8.7.
Affected Software
1 affected component
magepeopleteam WpTravelly<=1.8.7
Remediation
Information
Update the WordPress WpTravelly plugin to the latest available version (at least 1.8.8).
Event History
Apr 1, 2025
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-30892?
CVE-2025-30892 is considered a high severity vulnerability due to its potential for object injection and exploitation.
2
What does CVE-2025-30892 affect?
CVE-2025-30892 affects the WpTravelly plugin by magepeopleteam in versions up to and including 1.8.7.
3
How do I fix CVE-2025-30892?
To fix CVE-2025-30892, upgrade the WpTravelly plugin to the latest version provided by magepeopleteam.
4
Can CVE-2025-30892 lead to remote code execution?
Yes, CVE-2025-30892 can potentially allow remote code execution via object injection if exploited by an attacker.
5
Is there a patch available for CVE-2025-30892?
Yes, a patch is available in the latest version of the WpTravelly plugin released after version 1.8.7.