Impact
Deserialization of untrusted data allows an attacker to inject serialized objects into the NHR Options Table Manager plugin. The flaw, identified as CWE-502, can enable object injection that may lead to arbitrary code execution or privilege escalation on the WordPress host. The impact is a full compromise of the victim site’s integrity and confidentiality.
Affected Systems
WordPress installations that use the NHR Options Table Manager plugin version 1.1.2 or earlier are affected. This includes any site where the plugin is active and has not been updated beyond 1.1.2.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, while the EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require the attacker to supply crafted serialized data to the plugin, likely through an admin endpoint or a site frontend that processes such data. No additional prerequisites are documented, implying that a simple crafted request could trigger the flaw.
OpenCVE Enrichment
EUVD