CVE-2025-30892

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 1, 2025
Updated: Apr 2, 2025
CWE ID 502

Summary

CVE-2025-30892 is a Deserialization of Untrusted Data vulnerability affecting the magepeopleteam WpTravelly plugin. This issue permits Object Injection, allowing attackers to execute malicious code on impacted systems. The flaw impacts WpTravelly versions from n/a through 1.8.7, underscoring the need for prompt patching to mitigate potential security risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Wptravelly Plugin

Affected Vendors

  • WordPress