CVE-2025-39527

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 502

Summary

CVE-2025-39527 is a deserialization vulnerability affecting the Rating plugin by BestWebSoft. An attacker can exploit this issue, identified in versions 1.0 through 1.7, to inject objects and gain unauthorized access to affected systems. This vulnerability arises due to the plugin's failure to properly validate and sanitize user input, making it susceptible to deserialization of untrusted data. Successful exploitation can lead to serious security consequences, including potential data theft or system compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share