CVE-2025-47530: WordPress WPFunnels plugin <= 3.5.18 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels allows Object Injection. This issue affects WPFunnels: from n/a through 3.5.18.
Other sources
Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affects WPFunnels: from n/a through <= 3.5.18.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47530?
CVE-2025-47530 is classified as a medium severity vulnerability due to its potential for object injection attacks.
How do I fix CVE-2025-47530?
To fix CVE-2025-47530, update the WPFunnels plugin to the latest version that is not affected by this vulnerability.
What versions of WPFunnels are affected by CVE-2025-47530?
CVE-2025-47530 affects WPFunnels versions up to and including 3.5.18.
What type of vulnerability is CVE-2025-47530?
CVE-2025-47530 is a deserialization of untrusted data vulnerability that allows object injection.
Can CVE-2025-47530 lead to further security issues?
Yes, if exploited, CVE-2025-47530 could allow attackers to execute arbitrary PHP code and potentially gain control over the affected application.