
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64227 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the "Client Invoicing by Sprout Invoices" WordPress plugin developed by BoldGrid. It affects all versions up to and including 20.8.7 and allows unauthenticated remote attackers to perform object injection attacks. The vulnerability was reported on May 27, 2025, by researcher mcdruid and published by Patchstack on September 2, 2025; it was assigned a CVE on December 18, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502 / CAPEC-586: Object Injection), classified under OWASP Top 10 A3: Injection. An unauthenticated remote attacker can submit a crafted serialized PHP object payload to the plugin, which is deserialized without adequate validation. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress installation or its plugins/themes, this can be leveraged to achieve code injection, SQL injection, path traversal, or denial of service. No authentication or user interaction is required, and attack complexity is low (Patchstack).
Successful exploitation can result in full compromise of the affected WordPress site, including arbitrary code execution, SQL injection, path traversal, and denial of service — contingent on the presence of a usable POP chain in the environment. The vulnerability has high impact on confidentiality, integrity, and availability, potentially exposing sensitive invoice and client data, enabling unauthorized administrative access, and facilitating lateral movement within the hosting environment. Given the unauthenticated attack vector, mass-exploit campaigns targeting thousands of WordPress sites simultaneously are a realistic threat (Patchstack).
As of the time of disclosure, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Patchstack). The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class and CVSS score are frequently targeted in mass-exploit campaigns against WordPress sites.
O:, a:, or s: in request parameters); unexpected outbound connections from the web server to external IPs.wp-content/uploads/ or plugin directories.php, bash, curl, wget); unexpected cron jobs or scheduled tasks added to the server.The vendor has released version 20.8.8 of the Client Invoicing by Sprout Invoices plugin, which patches this vulnerability. All users running version 20.8.7 or earlier should update immediately to 20.8.8 or later via the WordPress admin dashboard or by downloading from the WordPress plugin repository. As interim mitigations: restrict access to the WordPress admin panel, deploy WAF rules (Patchstack has issued a virtual patch/mitigation rule for its users), implement input validation and sanitization at the application layer, and monitor system logs for suspicious activity (Patchstack).
The vulnerability was reported through Patchstack's Active Vulnerability Disclosure Program (VDP) by researcher mcdruid and received attention from automated security feeds and community aggregators including TheHackerWire on Mastodon and CVE tracking accounts on Bluesky. Patchstack flagged it as high priority and noted that vulnerabilities of this class are commonly used in mass-exploit campaigns against WordPress sites. No major vendor statements or in-depth researcher write-ups beyond the Patchstack advisory have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."