CVE advisoryCRITICAL
CVE-2025-4665
WordPress CFDB7 SQL Injection to PHP Object Injection
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A WordPress plugin contains a critical pre-authentication SQL injection vulnerability that can lead to insecure PHP object deserialization. This means unauthenticated attackers can potentially inject malicious code and execute arbitrary commands on affected websites by sending specially crafted input to the plugin. The