Impact
The vulnerability is a deserialization flaw that allows PHP object injection in PickPlugins Testimonial Slider plugin versions up to 2.0.13. By supplying a crafted serialized object to the plugin’s data handling routine, an attacker can force the creation of arbitrary PHP objects, enabling arbitrary code execution on the affected WordPress sites. This breach can compromise site confidentiality, integrity, and availability, potentially leading to full server compromise.
Affected Systems
The affected system is the WordPress Testimonial Slider plugin by PickPlugins. Versions from the initial release through 2.0.13 are vulnerable; any site installing these releases is at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity. The EPSS score of less than 1% suggests that, at present, widespread exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Based on the descriptive evidence, the likely attack path involves sending a malicious payload via a web request that feeds into the plugin’s serialization process, such as a form submission or API endpoint that accepts untrusted data. Successful exploitation would allow remote code execution against the web server or the WordPress instance.
OpenCVE Enrichment
EUVD