CVE-2025-4803 is a PHP Object Injection vulnerability affecting the Glossary by WPPedia – Best Glossary plugin for WordPress, versions 1.3.0 and earlier. Authenticated attackers with Administrator-level access can exploit this by injecting a PHP Object through the 'posttypes' parameter. The CVSS score is 7.2 (HIGH), indicating a severe impact on confidentiality, integrity, and availability if a suitable POP chain from another plugin or theme is present. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Steinrein | Glossary By WPPedia – Best Glossary Plugin For WordPress | >= 0, <= 1.3.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.