CVE-2025-49380: WordPress WooCommerce Vehicle Parts Finder plugin <= 3.7 - PHP Object Injection vulnerability
Published Oct 22, 2025
·Updated
Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7.
Affected Software
2 affected components
wpinstinct WooCommerce Vehicle Parts Finder<=3.7
WordPress WooCommerce Vehicle Parts Finder<=3.7
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49380?
CVE-2025-49380 is classified as a high severity vulnerability due to the potential for object injection attacks.
2
How do I fix CVE-2025-49380?
To fix CVE-2025-49380, update the WooCommerce Vehicle Parts Finder plugin to a version higher than 3.7.
3
What is the impact of CVE-2025-49380?
CVE-2025-49380 allows attackers to exploit deserialization of untrusted data, leading to object injection.
4
Which versions are affected by CVE-2025-49380?
CVE-2025-49380 affects the WooCommerce Vehicle Parts Finder plugin versions up to and including 3.7.
5
Who is the vendor for CVE-2025-49380?
The vendor for CVE-2025-49380 is wpinstinct, associated with the WooCommerce Vehicle Parts Finder plugin.