CVE-2025-32927: WordPress FoodBakery plugin <= 3.3 - PHP Object Injection vulnerability
Published May 19, 2025
·Updated
Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery wp-foodbakery allows Object Injection.This issue affects FoodBakery: from n/a through <= 3.3.
Affected Software
3 affected components
Chimpstudio FoodBakery<=3.3
WordPress FoodBakery plugin<=3.3
Chimpgroup Foodbakery Wordpress<=3.3
Event History
May 19, 2025
CVE Published
via MITRE·07:54 PM
Data Sourced
via MITRE·07:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-32927?
CVE-2025-32927 is classified as a Medium severity vulnerability.
2
How do I fix CVE-2025-32927?
To fix CVE-2025-32927, update Chimpstudio FoodBakery to the latest version beyond 3.3.
3
Who is affected by CVE-2025-32927?
CVE-2025-32927 affects users of Chimpstudio FoodBakery versions up to and including 3.3.
4
What type of vulnerability is CVE-2025-32927?
CVE-2025-32927 is a Deserialization of Untrusted Data vulnerability that allows for Object Injection.
5
What is the impact of CVE-2025-32927?
The impact of CVE-2025-32927 can lead to unauthorized remote code execution or data manipulation.