CVE-2025-48134: WordPress WP Tabs plugin <= 2.2.12 - PHP Object Injection Vulnerability
Published May 16, 2025
·Updated
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs wp-expand-tabs-free allows Object Injection.This issue affects WP Tabs: from n/a through <= 2.2.12.
Affected Software
3 affected components
ShapedPlugin WP Tabs<=2.2.11
WordPress WP Tabs<=2.2.11
ShapedPlugin Wp Tabs Wordpress<=2.2.11
Event History
May 16, 2025
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48134?
CVE-2025-48134 is classified as a high severity vulnerability due to its potential for object injection attacks.
2
How do I fix CVE-2025-48134?
To fix CVE-2025-48134, update WP Tabs to version 2.2.12 or later as it addresses this deserialization vulnerability.
3
What is the impact of CVE-2025-48134?
The impact of CVE-2025-48134 includes the possibility for attackers to execute arbitrary code through object injection.
4
Which versions of WP Tabs are affected by CVE-2025-48134?
CVE-2025-48134 affects WP Tabs from versions n/a through 2.2.11.
5
Is CVE-2025-48134 exploitative?
Yes, CVE-2025-48134 can be exploited by attackers to manipulate sensitive data or compromise the site.