External risk intelligence

Subscribe to Download Object Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-60224

This vulnerability affects a WordPress plugin designed for public-facing website functionality. Such plugins are commonly exposed to the internet as part of standard web application deployments, making the vulnerable code path reachable by external users.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A deserialization vulnerability in the Subscribe to Download WordPress plugin could allow an attacker to inject malicious objects, potentially leading to unauthorized control or data compromise. This issue is critical due to its network-accessible nature and high impact.

  • Untrusted data can be injected.
  • Critical plugin could be compromised.
  • Confirm relevance and exposure to risk.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted data to a vulnerable WordPress website that has the Subscribe to Download plugin installed. This data, when processed by the plugin, could lead to the execution of arbitrary code on the server.

  • No authentication required to attack.
  • Triggered by deserializing untrusted data.
  • Leads to code execution and data compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow an attacker to inject and execute arbitrary code on the affected system. This could occur when the plugin processes untrusted data, potentially leading to unauthorized access or disruption of services.

  • Plugin data could be exposed.
  • Untrusted data processing may lead to injection.
  • System control could be compromised.

Operational Fix

Recommended remediation, mitigation, and detection steps

This deserialization vulnerability in the Subscribe to Download plugin impacts WordPress sites where the plugin is deployed. Application owners, working with infrastructure or platform teams, should initiate the response by identifying all instances of the plugin, assessing their internet reachability and criticality, and determining the accountable owner before planning remediation.

  • Application owners should drive remediation.
  • Verify plugin reachability and business impact.
  • Plan coordinated updates or mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Subscribe to Download WordPress plugin?

Subscribe to Download is a plugin for WordPress websites designed to gate content. It requires visitors to provide their email address or subscribe before they can download specific files. This functionality typically places the plugin's code in a position to handle incoming traffic and data requests from site visitors, which is why it is often found on public-facing pages.

What does deserialization of untrusted data mean for CVE-2025-60224?

This is a weakness known as CWE-502, or Object Injection. In plain terms, the plugin takes data provided by an outside user and attempts to rebuild it into a complex programming object without enough safety checks. Because the plugin blindly trusts this incoming information, an attacker can supply a malicious object that forces the website to perform unintended, harmful actions.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted piece of data to the plugin. Because the bug resides in how the software processes this input, it does not require the attacker to have an account or log into the website first. It is important to note that just having the plugin installed is the primary requirement; the code must be actively processing input to be at risk.

Is my website at risk from this vulnerability?

According to Halo Surface Signal, this vulnerability is considered a high priority for investigation. Because the Subscribe to Download plugin is intended to provide public-facing functionality on WordPress sites, the code path required to exploit the bug is frequently exposed to the internet. If your site uses this plugin, it is likely reachable by external, unauthenticated users.

What steps should I take if I use this plugin?

Start by auditing your WordPress environment to confirm if the Subscribe to Download plugin is installed and active. Once identified, document which pages use this plugin to understand how it is exposed to the internet. Coordinate with your team to determine the plugin's role in your business operations, which will help prioritize the transition to a patched version or an alternative solution.

References