๐Ÿ” CVE Alert

CVE-2025-30985

UNKNOWN 0.0

WordPress GNUCommerce plugin <= 1.5.4 - PHP Object Injection vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a through <= 1.5.4.

CWE CWE-502
Vendor kagla
Product gnucommerce
Published Apr 15, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for kagla gnucommerce

Be the first to know when new unknown vulnerabilities affecting kagla gnucommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kagla / GNUCommerce
0 โ‰ค 1.5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/gnucommerce/vulnerability/wordpress-gnucommerce-plugin-1-5-4-php-object-injection-vulnerability?_s_id=cve

Credits

LVT-tholv2k | Patchstack Bug Bounty Program