Impact
Deserialization of untrusted data in the Saoshyant Slider plugin, a CWE-502 (Untrusted Deserialization) weakness, enables PHP Object Injection, allowing an attacker to inject malicious objects and execute arbitrary code on a vulnerable WordPress site.
Affected Systems
WordPress installations running Saoshyant Slider version 3.0 or earlier, provided by vendor saoshyant1994.
Risk and Exploitability
The CVSS score of 9.8 indicates a severe vulnerability, but the EPSS score of less than 1% shows a very low probability of exploitation in the near term. The flaw is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed. An attacker could exploit the weakness by submitting crafted payloads that are deserialized by the plugin, typically via user input fields or internal plugin operations. If successful, the attacker would gain remote code execution capabilities on the affected server.
OpenCVE Enrichment
EUVD