CVE-2025-32569: WordPress TableOn plugin <= 1.0.4.3 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Object Injection. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.2.
Other sources
Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.This issue affects TableOn: from n/a through <= 1.0.4.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32569?
CVE-2025-32569 has been classified as a critical vulnerability due to its potential for object injection and untrusted data deserialization.
How do I fix CVE-2025-32569?
To fix CVE-2025-32569, update the RealMag777 TableOn – WordPress Posts Table Filterable plugin to version 1.0.3 or later.
Which versions are affected by CVE-2025-32569?
CVE-2025-32569 affects RealMag777 TableOn – WordPress Posts Table Filterable versions up to and including 1.0.2.
What type of vulnerability is CVE-2025-32569?
CVE-2025-32569 is a deserialization of untrusted data vulnerability that allows for object injection.
Who is the vendor of the affected software in CVE-2025-32569?
The vendor of the affected software in CVE-2025-32569 is RealMag777.