CVE-2025-48336: WordPress Course Builder < 3.6.6 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in ThimPress Course Builder allows Object Injection.This issue affects Course Builder: from n/a before 3.6.6.
Other sources
Deserialization of Untrusted Data vulnerability in ThimPress Course Builder course-builder allows Object Injection.This issue affects Course Builder: from n/a through < 3.6.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48336?
CVE-2025-48336 is considered a critical vulnerability due to its potential for object injection and exploitation.
How do I fix CVE-2025-48336?
To fix CVE-2025-48336, update ThimPress Course Builder or WordPress Course Builder to version 3.6.6 or later.
What versions are affected by CVE-2025-48336?
CVE-2025-48336 affects all versions of ThimPress Course Builder and WordPress Course Builder prior to 3.6.6.
What types of attacks can leverage CVE-2025-48336?
CVE-2025-48336 can be exploited for remote code execution and data manipulation through deserialization attacks.
Who is the vendor associated with CVE-2025-48336?
The vendor associated with CVE-2025-48336 is ThimPress for the Course Builder plugin.