Impact
This vulnerability is a deserialization of untrusted data flaw, allowing a remote attacker to craft malicious PHP objects that, when unserialized by the CBX Poll plugin, can lead to arbitrary PHP code execution or unauthorized system access. The weakness is classified as CWE‑502.
Affected Systems
The flaw affects the WordPress CBX Poll plugin developed by Sabuj Kundu, for all supported versions up to and including 2.0.4. Users with older or unpatched installations are susceptible.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity, while the EPSS value of less than 1% suggests current exploitation potential remains low. The vulnerability is not yet listed in CISA’s KEV catalog, indicating no publicly disclosed exploitation. The most likely attack path involves an attacker sending a specially crafted payload to the plugin’s deserialization routine over the network, which is a remote attack vector inferred from the nature of the flaw.
OpenCVE Enrichment
EUVD