CVE · Critical

CVE-2025-60245 — WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-60245 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13 Deserialization of Untrusted Data Critical 9.8 < 2.9.13 2.9.13 2025-05-19

CVE-2025-60245

The User Manager plugin for WordPress contains a vulnerability that allows attackers with subscriber-level access and above to inject malicious PHP objects into the application through untrusted input deserialization. This flaw can be exploited by authenticated users, potentially leading to severe consequences such as file deletion, sensitive data exposure, or unauthorized code execution if other vulnerable plugins or themes are present on the system. The vulnerability affects plugin versions up to 2.9.12.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.