CVE-2025-30892
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 1, 2025
Updated: Apr 2, 2025
CWE ID 502
Summary
CVE-2025-30892 is a Deserialization of Untrusted Data vulnerability affecting the magepeopleteam WpTravelly plugin. This issue permits Object Injection, allowing attackers to execute malicious code on impacted systems. The flaw impacts WpTravelly versions from n/a through 1.8.7, underscoring the need for prompt patching to mitigate potential security risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Wptravelly Plugin
Affected Vendors
- WordPress