Impact
Deserialization of untrusted data in the WC Price History for Omnibus plugin allows attackers to inject PHP objects and execute arbitrary code. The flaw is a classic PHP Object Injection vulnerability (CWE-502). A malicious payload can lead to remote code execution, compromising the integrity and confidentiality of the WordPress site.
Affected Systems
Affected are installations of the kkarpieszuk WC Price History for Omnibus plugin for WordPress in versions up to and including 2.1.4. Any WordPress site that has this plugin active and has not applied a newer version is at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity risk, while the EPSS score of 19% suggests a moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers could potentially exploit the flaw remotely by sending crafted payloads through plugin inputs or other deserialization points, assuming the plugin processes untrusted data without safeguards.
OpenCVE Enrichment