CVE-2025-49455
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-49455 is a critical vulnerability affecting WordPress plugins/themes, with two distinct associations reported across sources. The NVD describes it as a Blind SQL Injection vulnerability (CWE-89) in the ClickandPledge WordPress-WPJobBoard plugin (versions through 25.07010000-WP6.8.1-JB5.11.5), while the ENISA EUVD and Patchstack associate the same CVE with a Deserialization of Untrusted Data (CWE-502) / PHP Object Injection vulnerability in the LoftOcean TinySalt WordPress theme (versions before 3.10.0). Both carry a CVSS v3.1 base score of 9.8 (Critical), requiring no authentication or user interaction. The vulnerability was published on June 10, 2025, and assigned by Patchstack (Red Hat CVE, ENISA EUVD).

Technical details

The primary technical characterization from Patchstack and ENISA EUVD identifies this as a Deserialization of Untrusted Data vulnerability (CWE-502) in the LoftOcean TinySalt WordPress theme, enabling PHP Object Injection (CAPEC-586). An unauthenticated remote attacker can supply crafted serialized PHP data to a vulnerable deserialization endpoint, potentially triggering gadget chains within the application to execute arbitrary code or manipulate application logic. The NVD additionally classifies the vulnerability as a Blind SQL Injection (CWE-89) in the WPJobBoard plugin, where unsanitized user input is passed directly into SQL queries, allowing inference-based data extraction without direct output. Both attack vectors require no privileges and no user interaction, with low attack complexity over the network (ENISA EUVD, Red Hat CVE).

Impact

Successful exploitation of either vulnerability variant could result in complete compromise of the affected WordPress installation, with high impact to confidentiality, integrity, and availability. In the deserialization scenario, an attacker could achieve remote code execution, enabling full server takeover, data exfiltration, or deployment of malware. In the SQL injection scenario, an attacker could extract sensitive database contents — including user credentials, personal data, and configuration secrets — and potentially modify or delete database records. Both scenarios could facilitate lateral movement within a shared hosting environment (ENISA EUVD, Red Hat CVE).

Exploitability

There is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation at this time. The EPSS score is approximately 0.041% (0.000410), indicating a low current probability of exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (ENISA EUVD).

Mitigation and workarounds

For the TinySalt WordPress theme, upgrade to version 3.10.0 or later, which contains the fix for the deserialization vulnerability. For the WPJobBoard plugin, upgrade to a version beyond 25.07010000-WP6.8.1-JB5.11.5 once a patched release is available. General hardening steps include implementing strict input validation, using allow-lists for acceptable object types during deserialization, applying the principle of least privilege to database accounts, and monitoring/logging deserialization and database query activity. Site administrators should also consider using a WordPress security plugin (e.g., Wordfence) to detect exploitation attempts (ENISA EUVD, Wordfence Weekly).

Community reactions

Wordfence included CVE-2025-49455 in its weekly WordPress vulnerability report for the period of June 9–15, 2025, highlighting it as part of a broader set of critical WordPress plugin and theme vulnerabilities. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation (Wordfence Weekly).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16955NONEN/A
  • ai-engine
NoYesAug 08, 2026
CVE-2026-16953NONEN/A
  • ai-engine
NoYesAug 08, 2026
CVE-2026-16948NONEN/A
  • solace-extra
NoYesAug 08, 2026
CVE-2026-16608NONEN/A
  • download-monitor
NoYesAug 08, 2026
CVE-2026-16595NONEN/A
  • wpdirectorykit
NoYesAug 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management