9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12.
AI Analysis
PHP Object Injection vulnerability in WP User Manager plugin
Basic Information
ID
CVE-2025-60245
Source
Patchstack
Published
Nov 6, 2025 at 15:55
Modified
Nov 17, 2025 at 16:10
Affected Product
Vendor
WP User Manager
Product
WP User Manager
Version
n/a
Affected Versions
WP User Manager WP User Manager n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
WordPress
Product
WP User Manager
Version
<= 2.9.12