Impact
This vulnerability involves the deserialization of untrusted data within the WP Posts Carousel plugin, enabling an attacker to perform PHP object injection. The result is the potential execution of arbitrary PHP code, which can lead to full system compromise. The weakness is classified as CWE‑502 and carries a high CVSS score of 8.8, indicating a severe threat to confidentiality, integrity, and availability.
Affected Systems
The WP Posts Carousel plugin from teastudio.pl is affected in all releases up to and including version 1.3.12. No further version details are specified; users should verify that their installations are 1.3.12 or earlier.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 8.8 classifies it as high severity. The attack vector is inferred to be remote, requiring an attacker to supply a crafted serialized payload to the vulnerable plugin—likely through a publicly accessible endpoint or administrative interface. Given the possibility of remote code execution, the risk remains significant for exposed WordPress sites.
OpenCVE Enrichment
EUVD