CVE · High

CVE-2025-64353 — Polylang [polylang] < 3.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-64353 Polylang [polylang] < 3.7.4 Deserialization of Untrusted Data High 8.8 < 3.7.4 3.7.4 2025-10-28

CVE-2025-64353

Authenticated users with Contributor-level access and above can inject malicious PHP objects into Polylang versions up to 3.7.3 by exploiting a deserialization vulnerability in untrusted input. This flaw has no inherent consequences unless another plugin or theme containing a specific type of code injection is also installed, which could potentially enable attackers to delete files, extract sensitive information, or execute arbitrary code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.