CVE-2025-15672

CVE-2025-15672: Chama < 1.0.13 - Unauthenticated PHP Object Injection

Vendor Unknown
Product ChamaWP
Published August 3, 2026
Last update August 4, 2026

CVSS base score

What the vulnerability does

01Description

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.

Key dates

02Disclosure timeline

August 3, 2026 CVE published
August 4, 2026 Record updated