Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-12099
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12099 is a PHP Object Injection vulnerability in the Academy LMS – WordPress LMS Plugin for Complete eLearning Solution, affecting all versions up to and including 3.3.8. The flaw arises from deserialization of untrusted input in the import_all_courses function and requires Administrator-level authentication to exploit. It was published on November 8, 2025, with a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).

Technical details

The root cause is improper deserialization of untrusted data (CWE-502) within the import_all_courses function of the Academy LMS plugin. An authenticated attacker with Administrator-level access can supply a crafted serialized PHP object via this function, which the plugin deserializes without adequate validation. Exploitation impact is conditional: no known PHP Object Property (POP) chain exists within the vulnerable plugin itself, so actual harm depends on whether another installed plugin or theme provides a usable POP chain that can be triggered by the injected object (Red Hat CVE, Wordfence).

Impact

If a POP chain is available via another installed plugin or theme, a successful exploit could allow an authenticated administrator to delete arbitrary files, retrieve sensitive data, or achieve remote code execution on the WordPress host. Confidentiality, integrity, and availability are all rated High under the CVSS scoring. In the absence of a POP chain, the vulnerability has no direct exploitable impact beyond the injection of a PHP object (Red Hat CVE, Wordfence).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-12099. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.127%, indicating a low probability of exploitation in the near term. Exploitation is further constrained by the requirement for Administrator-level credentials and the conditional dependency on a POP chain from a co-installed plugin or theme (Red Hat CVE, Tenable).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Academy LMS plugin at version 3.3.8 or earlier, and enumerate other installed plugins or themes to identify any that contain a known PHP POP chain.
  2. Authentication: Obtain or compromise Administrator-level credentials for the target WordPress site (e.g., via credential stuffing, phishing, or reuse of leaked credentials).
  3. Craft malicious payload: Construct a serialized PHP object that, when deserialized, triggers a POP chain available in one of the co-installed plugins or themes to perform the desired malicious action (e.g., file deletion, data exfiltration, or code execution).
  4. Trigger deserialization: Authenticate to the WordPress admin panel and invoke the import_all_courses function with the crafted serialized payload as input.
  5. Achieve objective: The deserialized object triggers the POP chain, resulting in arbitrary file deletion, sensitive data retrieval, or remote code execution depending on the chain available (Red Hat CVE, Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to the import_all_courses endpoint with unexpected or encoded serialized data in the request body.
  • File System: Unexpected file deletions, new or modified PHP files in the WordPress installation directory, or newly created web shells.
  • Process: Unusual PHP child processes spawned by the web server process (e.g., curl, wget, bash) following an import action.
  • Network: Outbound connections from the web server to unknown external IPs shortly after an import_all_courses action is performed.

Mitigation and workarounds

Users should update the Academy LMS plugin to a version beyond 3.3.8 as soon as a patched release is available from the plugin vendor. In the interim, restrict Administrator access to trusted users only and audit co-installed plugins and themes for known POP chains that could amplify this vulnerability. Implementing a Web Application Firewall (WAF) rule to block suspicious serialized PHP object payloads in import-related requests can provide additional defense-in-depth (Wordfence, Red Hat CVE).

Community reactions

Wordfence included CVE-2025-12099 in its weekly WordPress vulnerability report for November 3–9, 2025, noting the conditional nature of the risk (Wordfence). The vulnerability was also picked up by automated security feeds on Mastodon and Bluesky shortly after publication, though no significant expert commentary or media coverage has been identified beyond routine vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93031HIGH8.8
  • use-your-drive
NoYesSep 18, 2026
CVE-2026-87915HIGH7.2
  • popup-maker
NoYesSep 18, 2026
CVE-2026-18405HIGH7.2
  • jeg-elementor-kit
NoYesSep 18, 2026
CVE-2026-15797MEDIUM6.4
  • popup-maker
NoYesSep 18, 2026
CVE-2026-90884MEDIUM5.4
  • wp-recipe-maker
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management