CVE-2025-32647: WordPress Question Answer plugin <= 1.2.73 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer allows Object Injection. This issue affects Question Answer: from n/a through 1.2.70.
Other sources
Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer question-answer allows Object Injection.This issue affects Question Answer: from n/a through <= 1.2.73.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32647?
CVE-2025-32647 is classified as a critical vulnerability due to its potential for object injection attacks.
How do I fix CVE-2025-32647?
To fix CVE-2025-32647, upgrade the WordPress Question Answer Plugin to a version beyond 1.2.70.
What platforms are affected by CVE-2025-32647?
CVE-2025-32647 affects the WordPress Question Answer Plugin from versions prior to 1.2.71.
Can CVE-2025-32647 lead to remote code execution?
Yes, CVE-2025-32647 can potentially allow an attacker to execute arbitrary code due to object injection.
How can I identify if CVE-2025-32647 is exploited on my site?
Monitoring logs for unusual activity or unexpected behavior in your WordPress site can help identify exploitation of CVE-2025-32647.