CVE-2025-49380
Published: 22 October 2025
Summary
CVE-2025-49380 is a critical-severity Deserialization of Untrusted Data (CWE-502) vulnerability. Its CVSS base score is 9.8 (Critical).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 26.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 RA-5 (Vulnerability Monitoring and Scanning) and SI-10 (Information Input Validation).
Deeper analysis
CVE-2025-49380 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the wpinstinct WooCommerce Vehicle Parts Finder plugin (woo-vehicle-parts-finder) for WordPress. The flaw allows Object Injection and affects all versions from n/a through 3.7.
The vulnerability carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating it is exploitable remotely over the network by unauthenticated attackers with low attack complexity and no user interaction. Exploitation can result in high impacts to confidentiality, integrity, and availability, potentially enabling arbitrary code execution or server compromise via injected objects.
Patchstack's advisory at https://patchstack.com/database/Wordpress/Plugin/woo-vehicle-parts-finder/vulnerability/wordpress-woocommerce-vehicle-parts-finder-plugin-3-7-php-object-injection-vulnerability?_s_id=cve provides further details on the vulnerability, including mitigation guidance for affected WordPress installations.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-35552
Vulnerability details
Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Direct remote unauthenticated RCE via unsafe PHP deserialization in a public-facing WordPress plugin.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly requires timely patching and remediation of the deserialization of untrusted data flaw in WooCommerce Vehicle Parts Finder plugin versions <=3.7 to prevent object injection and exploitation.
Enforces validation of untrusted inputs prior to deserialization, blocking malicious serialized objects that enable object injection in the vulnerable plugin.
Vulnerability scanning identifies the deserialization vulnerability (CVE-2025-49380) in the plugin, enabling prompt flaw remediation.