CVE-2025-39550: WordPress FluentCommunity plugin <= 1.2.15 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity allows Object Injection. This issue affects FluentCommunity: from n/a through 1.2.15.
Other sources
Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Object Injection.This issue affects FluentCommunity: from n/a through <= 1.2.15.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39550?
CVE-2025-39550 is classified as a high severity vulnerability due to its potential for object injection and exploitation.
How do I fix CVE-2025-39550?
To fix CVE-2025-39550, update Shahjahan Jewel FluentCommunity to the latest version beyond 1.2.15.
What vulnerabilities does CVE-2025-39550 expose in FluentCommunity?
CVE-2025-39550 exposes the risk of deserialization of untrusted data, allowing for potential remote code execution.
Which versions of FluentCommunity are affected by CVE-2025-39550?
CVE-2025-39550 affects FluentCommunity versions from n/a to 1.2.15.
Is CVE-2025-39550 specific to a particular platform?
CVE-2025-39550 is primarily associated with Shahjahan Jewel FluentCommunity and WordPress FluentCommunity.