CVE-2025-48101: WordPress Constant Contact for WordPress Plugin <= 4.1.1 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1.
Other sources
Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress constant-contact-api allows Object Injection.This issue affects Constant Contact for WordPress: from n/a through <= 4.1.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48101?
CVE-2025-48101 has a medium severity rating due to its potential for object injection which could lead to critical vulnerabilities.
How do I fix CVE-2025-48101?
To fix CVE-2025-48101, update the Constant Contact for WordPress plugin to version 4.1.2 or later.
What versions of Constant Contact for WordPress are affected by CVE-2025-48101?
CVE-2025-48101 affects versions of Constant Contact for WordPress from n/a through 4.1.1.
What type of vulnerability is CVE-2025-48101?
CVE-2025-48101 is a Deserialization of Untrusted Data vulnerability that allows for Object Injection.
Is there a workaround for CVE-2025-48101 if I cannot immediately update?
If you cannot update immediately for CVE-2025-48101, consider disabling the plugin until a patch is applied.