Cozmoslabs TranslatePress Deserialization of Untrusted Data Vulnerability Allowing Object Injection

Vulnerability

A deserialization of untrusted data vulnerability has been identified in the Cozmoslabs TranslatePress plugin, specifically in versions through 2.10.2. This vulnerability allows for object injection, which could be exploited under certain conditions.

Impact

Exploitation of this vulnerability could lead to object injection, a type of vulnerability where an attacker can manipulate the application's object handling, potentially leading to more severe issues such as code execution or application compromise.

Added: Nov 6, 2025, 4:42 PM
Updated: Nov 6, 2025, 9:11 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
7.6
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.