CVE-2025-32143: WordPress Accordion plugin <= 2.3.11 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue affects Accordion: from n/a through <= 2.3.11.
Other sources
Deserialization of Untrusted Data vulnerability in PickPlugins Accordion allows Object Injection. This issue affects Accordion: from n/a through 2.3.10.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32143?
CVE-2025-32143 has a medium severity rating due to its potential for object injection attacks.
How do I fix CVE-2025-32143?
To mitigate CVE-2025-32143, update PickPlugins Accordion to version 2.3.11 or later.
What types of attacks can CVE-2025-32143 allow?
CVE-2025-32143 can allow object injection attacks that could lead to unauthorized data access or remote code execution.
Which versions of PickPlugins Accordion are affected by CVE-2025-32143?
CVE-2025-32143 affects PickPlugins Accordion versions from n/a up to and including 2.3.10.
Is CVE-2025-32143 a widespread issue?
The impact of CVE-2025-32143 may vary, but it poses a risk to any site using the vulnerable versions of PickPlugins Accordion.