CVE-2025-58592: WordPress TranslatePress Plugin <= 2.10.2 - Deserialization of untrusted data Vulnerability
Published Nov 6, 2025
·Updated
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.10.2.
Affected Software
2 affected components
Cozmoslabs TranslatePress<=2.10.2
WordPress TranslatePress Plugin<=2.10.2
Event History
Nov 6, 2025
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-58592?
CVE-2025-58592 has a high severity due to its potential for object injection, which could lead to serious security breaches.
2
How do I fix CVE-2025-58592?
To fix CVE-2025-58592, upgrade the TranslatePress plugin to version 2.10.3 or later.
3
What systems are affected by CVE-2025-58592?
CVE-2025-58592 affects Cozmoslabs TranslatePress versions from n/a through 2.10.2.
4
What type of vulnerability is CVE-2025-58592?
CVE-2025-58592 is classified as a Deserialization of Untrusted Data vulnerability.
5
What impact does CVE-2025-58592 have?
CVE-2025-58592 can allow an attacker to perform object injection attacks, risking exploitation of the application.