CVE-2025-68038: WordPress Icegram Express Pro plugin < 5.9.14 - PHP Object Injection vulnerability
Published Dec 24, 2025
·Updated
Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Icegram Express Pro: from n/a through < 5.9.14.
Affected Software
1 affected component
Icegram Icegram Express Pro<5.9.14
Event History
Dec 24, 2025
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-68038?
CVE-2025-68038 has a high severity rating due to its potential for object injection attacks.
2
How do I fix CVE-2025-68038?
To fix CVE-2025-68038, upgrade Icegram Express Pro to version 5.9.12 or later.
3
What versions of Icegram Express Pro are affected by CVE-2025-68038?
CVE-2025-68038 affects Icegram Express Pro versions up to and including 5.9.11.
4
What kind of vulnerability is CVE-2025-68038?
CVE-2025-68038 is a deserialization of untrusted data vulnerability that allows for object injection.
5
Who is affected by CVE-2025-68038?
Users of Icegram Express Pro versions up to 5.9.11 are at risk of being affected by CVE-2025-68038.