Impact
Object injection occurs when the plugin deserializes untrusted data, allowing an attacker to instantiate arbitrary PHP objects and potentially execute arbitrary code, thereby compromising the WordPress site. The weakness is classified as CWE‑502.
Affected Systems
All installations of the Muzaara Google Ads Report WordPress plugin, versions up to and including 3.1, are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8, indicating it is critical. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation, and it is not listed in the CISA KEV catalog. Exploitation would most likely occur via the plugin’s handling of untrusted input—such as configuration data or API requests—though the exact attack vector is inferred from the description.
OpenCVE Enrichment
EUVD