PT-2025-44605 · Polylang · Polylang

Published

2025-10-31

·

Updated

2025-10-31

·

CVE-2025-64353

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chouby Polylang versions through 3.7.3
Description The Polylang software contains a flaw related to the deserialization of untrusted data, which can lead to object injection. This issue allows for potential malicious code execution through the processing of improperly serialized data.
Recommendations Update Polylang to a version newer than 3.7.3.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-64353

Affected Products

Polylang