First published: Thu Apr 24 2025(Updated: )
Deserialization of Untrusted Data vulnerability in djjmz Social Counter allows Object Injection. This issue affects Social Counter: from n/a through 2.0.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
djjmz Social Counter | >=2.0.5 | |
WordPress Social Counter | <=2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46473 is classified as a critical deserialization vulnerability that can lead to object injection.
To fix CVE-2025-46473, update the djjmz Social Counter plugin to the latest version that addresses the vulnerability.
CVE-2025-46473 affects djjmz Social Counter versions from n/a through 2.0.5 and WordPress Social Counter up to version 2.0.5.
Exploiting CVE-2025-46473 can allow an attacker to inject malicious objects leading to a wide range of exploits.
CVE-2025-46473 is specifically related to the djjmz and WordPress implementations of the Social Counter plugin.