Impact
Deserialization of untrusted data in the Digital Zoom Studio DZS Video Gallery plugin enables PHP object injection. An attacker could supply crafted serialized input that creates arbitrary PHP objects, potentially leading to arbitrary code execution on the host. The vulnerability is a CWE‑502 deserialization flaw, limited to the plugin code and does not directly affect the WordPress core.
Affected Systems
The vulnerability affects the Digital Zoom Studio DZS Video Gallery WordPress plugin versions up to and including 12.25. Systems running any of these plugin versions and exposing the plugin’s endpoints are at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS is below 1 %, suggesting low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to send serialized data to a vulnerable endpoint, a likely remote web‑based attack vector inferred from the description.
OpenCVE Enrichment