CVE Database /
CVE-2025-60245
CVE · Critical
CVE-2025-60245 — WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-60245
|
WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13 |
Deserialization of Untrusted Data |
Critical
9.8
|
< 2.9.13
|
2.9.13 |
2025-05-19 |
—
|
CVE-2025-60245
The User Manager plugin for WordPress contains a vulnerability that allows attackers with subscriber-level access and above to inject malicious PHP objects into the application through untrusted input deserialization. This flaw can be exploited by authenticated users, potentially leading to severe consequences such as file deletion, sensitive data exposure, or unauthorized code execution if other vulnerable plugins or themes are present on the system. The vulnerability affects plugin versions up to 2.9.12.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings