CVE-2025-15672: Unknown Chamawp

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.

Affected products

  • Unknown Chamawp: before 1.0.13 (fixed in 1.0.13)

Published 2026-08-03. Last modified 2026-09-29.