CVE-2025-64353
Authenticated users with Contributor-level access and above can inject malicious PHP objects into Polylang versions up to 3.7.3 by exploiting a deserialization vulnerability in untrusted input. This flaw has no inherent consequences unless another plugin or theme containing a specific type of code injection is also installed, which could potentially enable attackers to delete files, extract sensitive information, or execute arbitrary code.
Based on public CVE data (MITRE/NVD).