First published: Wed May 07 2025(Updated: )
Deserialization of Untrusted Data vulnerability in Mario Peshev WP-CRM System allows Object Injection. This issue affects WP-CRM System: from n/a through 3.4.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP-CRM System | <=3.4.1 | |
WP-CRM System | <=3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47629 is classified as a critical vulnerability due to its potential for remote code execution through object injection.
To fix CVE-2025-47629, update the WP-CRM System plugin to version 3.4.1 or higher.
CVE-2025-47629 affects all versions of WP-CRM System prior to and including version 3.4.1.
CVE-2025-47629 allows attackers to exploit deserialization of untrusted data, leading to object injection vulnerabilities.
Currently, the recommended action for CVE-2025-47629 is to update to the latest version, as no effective workaround has been published.