
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49386 is a Deserialization of Untrusted Data (PHP Object Injection) vulnerability in the WordPress plugin "Preserve Code Formatting" by Scott Reilly. It affects all versions up to and including 4.0.1, and was published on November 6, 2025, with the vulnerability originally reported on July 2, 2025, and disclosed publicly on August 1, 2025. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), requiring only low privileges and no user interaction to exploit over the network (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), enabling PHP Object Injection (CAPEC-586). The plugin fails to safely handle serialized data supplied by low-privileged users (Contributor/Developer role), allowing an attacker to inject a malicious PHP object. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress installation or its plugins, this can be leveraged to achieve arbitrary code execution, SQL injection, path traversal, or denial of service (Patchstack). The vulnerability was discovered and credited to researcher "mcdruid" (Patchstack).
Successful exploitation can result in complete system compromise, with high impact to confidentiality, integrity, and availability. An authenticated attacker with low privileges (Contributor or Developer role) can execute arbitrary code on the server, access or exfiltrate sensitive data, modify site content or database records, and potentially disrupt service availability. Depending on the POP chains available in the WordPress environment, the attacker may also pivot to other systems or escalate privileges further (Patchstack, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Patchstack). The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class (CVSS 8.8, low-complexity, network-accessible) are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
bash, curl, wget, python) that are not typical for normal WordPress operation.The vendor has released version 5.0 of the Preserve Code Formatting plugin, which resolves this vulnerability. All users should update immediately from version 4.0.1 or earlier to version 5.0 or later via the WordPress plugin dashboard or by downloading from the official WordPress plugin repository. As an interim measure, restrict Contributor and Developer role access to trusted users only, and consider using a Web Application Firewall (WAF) solution such as Patchstack, which has issued a virtual patch/mitigation rule to block exploitation attempts until the plugin is updated (Patchstack).
Patchstack, the coordinating security vendor, classified this as a medium-priority vulnerability despite the high CVSS score, noting that exploitability depends on the presence of a suitable POP chain in the target environment. The vulnerability was responsibly disclosed by researcher "mcdruid" and coordinated through Patchstack's VDP program (Patchstack). No significant broader media coverage or notable social media reactions have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."