CVE-2025-32658: WordPress HelpGent plugin <= 2.2.5 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in wpWax HelpGent allows Object Injection. This issue affects HelpGent: from n/a through 2.2.4.
Other sources
Deserialization of Untrusted Data vulnerability in wpWax HelpGent helpgent allows Object Injection.This issue affects HelpGent: from n/a through <= 2.2.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32658?
The severity of CVE-2025-32658 is considered high due to the potential for Object Injection attacks.
How do I fix CVE-2025-32658?
To fix CVE-2025-32658, update the wpWax HelpGent plugin to version 2.2.5 or later.
What does CVE-2025-32658 affect?
CVE-2025-32658 affects the wpWax HelpGent plugin versions up to and including 2.2.4.
What type of vulnerability is CVE-2025-32658?
CVE-2025-32658 is a Deserialization of Untrusted Data vulnerability that allows Object Injection.
Can CVE-2025-32658 lead to unauthorized access?
Yes, CVE-2025-32658 can lead to unauthorized access and execution of arbitrary code due to Object Injection.