Impact
Deserialization of untrusted data in mywebtonet PHP/MySQL CPU performance statistics allows an attacker to inject arbitrary PHP objects. This leads to remote code execution and full compromise of the affected WordPress site, including confidentiality, integrity, and availability. The vulnerability is an instance of CWE-502, deserialization of untrusted data.
Affected Systems
The vulnerability affects the WordPress plugin mywebtonet PHP/MySQL CPU performance statistics. Versions from the earliest available through 1.2.1 are impacted. Any WordPress installation with this plugin and a version identifier of 1.2.1 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 classifies the issue as critical, and the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker sending a crafted HTTP request that triggers the plugin’s deserialization routine; the plugin does not restrict input to trusted sources, so the exploit can be performed against publicly accessible WordPress sites. Once the payload is processed, arbitrary code can be executed on the server.
OpenCVE Enrichment
EUVD