CVE-2025-39550
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 17, 2025
CWE ID 502
Summary
CVE-2025-39550 is a Deserialization of Untrusted Data vulnerability affecting the Shahjahan Jewel FluentCommunity software. This issue permits Object Injection, allowing unauthorized code execution. The flaw is present in FluentCommunity versions from n/a through 1.2.15. Successful exploitation could lead to serious security implications, including system compromise or data theft. Users are strongly advised to update their software to the latest patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress