First published: Thu Apr 17 2025(Updated: )
Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer allows Object Injection. This issue affects Question Answer: from n/a through 1.2.70.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Question Answer Plugin | <=1.2.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32647 is classified as a critical vulnerability due to its potential for object injection attacks.
To fix CVE-2025-32647, upgrade the WordPress Question Answer Plugin to a version beyond 1.2.70.
CVE-2025-32647 affects the WordPress Question Answer Plugin from versions prior to 1.2.71.
Yes, CVE-2025-32647 can potentially allow an attacker to execute arbitrary code due to object injection.
Monitoring logs for unusual activity or unexpected behavior in your WordPress site can help identify exploitation of CVE-2025-32647.