
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69328 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the Booking and Rental Manager for WooCommerce WordPress plugin by magepeopleteam. It affects all versions up to and including 2.5.9, and was patched in version 2.6.0. The vulnerability was reported on November 25, 2025, and published on February 9–20, 2026. It carries a CVSS v3.1 base score of 8.8 (High), requiring only low-privilege authentication to exploit (Patchstack, Feedly).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), classified under OWASP Top 10 A3: Injection and mapped to CAPEC-586 (Object Injection). An authenticated attacker with Contributor-level privileges can supply a crafted serialized PHP object to the plugin, which is deserialized without adequate validation. If a suitable PHP Object Injection (POP) chain exists within the WordPress environment, this can be leveraged to achieve remote code execution, SQL injection, path traversal, or denial of service (Patchstack, Feedly).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress/WooCommerce installation. An attacker could achieve remote code execution, gain unauthorized access to sensitive data (including customer and booking information), modify or delete booking and rental records, and disrupt store operations. The scope of impact depends on the availability of a POP chain in the target environment, but in worst-case scenarios full system compromise is possible (Patchstack, Feedly).
No public proof-of-concept exploit has been confirmed, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. However, Patchstack notes that vulnerabilities of this CVSS severity class are frequently used in mass-exploit campaigns targeting WordPress sites at scale. No threat actor attribution or CISA KEV listing has been identified for this CVE (Patchstack, Feedly).
O: patterns in request bodies); unexpected outbound connections from the web server to external IPs.bash, curl, wget, python) following plugin interaction.siteurl, admin_email) in the wp_options table.The vendor (Magepeople Inc.) released version 2.6.0 of the Booking and Rental Manager for WooCommerce plugin, which patches this vulnerability. Site administrators should update immediately to version 2.6.0 or later via the WordPress plugin dashboard. As interim measures, restrict Contributor-level user registrations and permissions, and consider deploying a Web Application Firewall (WAF) rule to detect and block PHP object injection attempts. Patchstack users benefit from an automatic virtual patch (mitigation rule) that blocks exploitation until the plugin is updated (Patchstack).
Patchstack, which coordinated the disclosure, classified this as a medium-priority vulnerability and issued a virtual patch for its users. The vulnerability was credited to researcher Phat RiO, who reported it on November 25, 2025. Wordfence also included this CVE in its weekly WordPress vulnerability report for the period of February 9–15, 2026, indicating broad coverage within the WordPress security community (Patchstack, Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."