
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12099 is a PHP Object Injection vulnerability in the Academy LMS – WordPress LMS Plugin for Complete eLearning Solution, affecting all versions up to and including 3.3.8. The flaw arises from deserialization of untrusted input in the import_all_courses function and requires Administrator-level authentication to exploit. It was published on November 8, 2025, with a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).
The root cause is improper deserialization of untrusted data (CWE-502) within the import_all_courses function of the Academy LMS plugin. An authenticated attacker with Administrator-level access can supply a crafted serialized PHP object via this function, which the plugin deserializes without adequate validation. Exploitation impact is conditional: no known PHP Object Property (POP) chain exists within the vulnerable plugin itself, so actual harm depends on whether another installed plugin or theme provides a usable POP chain that can be triggered by the injected object (Red Hat CVE, Wordfence).
If a POP chain is available via another installed plugin or theme, a successful exploit could allow an authenticated administrator to delete arbitrary files, retrieve sensitive data, or achieve remote code execution on the WordPress host. Confidentiality, integrity, and availability are all rated High under the CVSS scoring. In the absence of a POP chain, the vulnerability has no direct exploitable impact beyond the injection of a PHP object (Red Hat CVE, Wordfence).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-12099. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.127%, indicating a low probability of exploitation in the near term. Exploitation is further constrained by the requirement for Administrator-level credentials and the conditional dependency on a POP chain from a co-installed plugin or theme (Red Hat CVE, Tenable).
import_all_courses function with the crafted serialized payload as input.import_all_courses endpoint with unexpected or encoded serialized data in the request body.curl, wget, bash) following an import action.import_all_courses action is performed.Users should update the Academy LMS plugin to a version beyond 3.3.8 as soon as a patched release is available from the plugin vendor. In the interim, restrict Administrator access to trusted users only and audit co-installed plugins and themes for known POP chains that could amplify this vulnerability. Implementing a Web Application Firewall (WAF) rule to block suspicious serialized PHP object payloads in import-related requests can provide additional defense-in-depth (Wordfence, Red Hat CVE).
Wordfence included CVE-2025-12099 in its weekly WordPress vulnerability report for November 3–9, 2025, noting the conditional nature of the risk (Wordfence). The vulnerability was also picked up by automated security feeds on Mastodon and Bluesky shortly after publication, though no significant expert commentary or media coverage has been identified beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."