Impact
The vulnerability occurs because the Weaver Show Posts WordPress plugin, versions older than 1.8.1, unserialises the content of an imported file without proper validation. This allows a user with administrative or higher privileges to upload a crafted file that, if the blog contains an appropriate gadget chain, can lead to PHP object injection and potential code execution on the affected site. The weakness is identified as CWE-502.
Affected Systems
WordPress sites that have the Weaver Show Posts plugin installed with a version earlier than 1.8.1. No other products or vendors were identified in the CVE data.
Risk and Exploitability
The CVSS score of 3.3 indicates a low severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to be privileged enough to import a file through the plugin’s interface; an appropriate gadget chain must already exist on the target site to exploit the object injection. Because of the high prerequisite and lack of publicly documented exploitation, the likelihood is low but not impossible for a determined internal adversary.
OpenCVE Enrichment