CVE-2025-66073: WordPress WP Webhooks plugin <= 3.3.8 - PHP Object Injection vulnerability
Published Nov 21, 2025
·Updated
Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8.
Affected Software
1 affected component
Cozmoslabs WP Webhooks<=3.3.8
Event History
Nov 21, 2025
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66073?
CVE-2025-66073 is categorized as a high severity vulnerability due to its potential for remote code execution through object injection.
2
How do I fix CVE-2025-66073?
To mitigate CVE-2025-66073, update WP Webhooks to version 3.3.9 or later.
3
What software is affected by CVE-2025-66073?
CVE-2025-66073 affects WP Webhooks versions from n/a through 3.3.8.
4
What type of vulnerability is CVE-2025-66073?
CVE-2025-66073 is a deserialization of untrusted data vulnerability that allows for object injection.
5
What are the potential impacts of CVE-2025-66073?
Exploitation of CVE-2025-66073 could lead to unauthorized access and execution of arbitrary PHP code on the affected system.