Impact
Deserialization of untrusted data in the kkarpieszuk WC Price History for Omnibus plugin allows an attacker to inject PHP objects and execute arbitrary code. This flaw, categorized as CWE-502, can compromise the integrity and confidentiality of a WordPress site by allowing remote code execution if exploited.
Affected Systems
Affected systems are WordPress sites that have installed the WC Price History for Omnibus plugin version 2.1.4 or earlier. Any instance where the plugin remains active without an upgrade is at risk.
Risk and Exploitability
The CVSS score of 7.2 reflects a high severity risk, while the EPSS score of 1% indicates a relatively low likelihood of exploitation. Based on the description, it is inferred that an attacker may trigger the vulnerability by sending crafted serialized payloads through plugin inputs or other deserialization points, assuming the plugin processes untrusted data without adequate safeguards. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment