CVE-2025-15672: Unknown Chamawp
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.
Affected products
- Unknown Chamawp: before 1.0.13 (fixed in 1.0.13)
Published 2026-08-03. Last modified 2026-09-29.