Impact
The ADFO admin‑form plugin accepts serialized data that is not properly validated, allowing attackers to craft serialized objects that are deserialized by the application. This flaw permits object injection, and the potential for remote code execution is inferred from the nature of object injection, though the CVE description does not explicitly state a confirmed RCE. The impact could include execution of arbitrary code, privilege escalation, or other malicious actions that compromise the confidentiality, integrity, or availability of a WordPress site.
Affected Systems
The vulnerability exists in the giuliopanda ADFO WordPress plugin versions up through 1.9.1. Any WordPress installation that has this plugin installed and has not been upgraded to a later version is affected.
Risk and Exploitability
The measured severity is a CVSS score of 7.2, indicating a high likelihood of serious impact. The EPSS score of less than 1 % suggests that, as of now, the probability of exploitation is low, and the flaw is not currently listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring an attacker to supply crafted input to the plugin’s deserialization logic, which is commonly achieved via a specially crafted HTTP request or API payload.
OpenCVE Enrichment
EUVD