Impact
The vulnerability is a deserialization flaw (CWE‑502) that allows PHP Object Injection. An attacker can supply crafted serialized data that, when processed by WP‑CRM System, instantiates arbitrary objects, potentially executing code on the server. This can lead to complete compromise of the site, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects the WP‑CRM System plugin for WordPress, versions from unknown release through 3.4.5. The plugin is distributed by Mario Peshev.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. The EPSS score of <1% implies a very low but non‑zero probability of exploitation in the wild. Since the vulnerability is not listed in the CISA KEV catalog, it has not yet been observed in widespread attacks. The likely attack vector is remote via HTTP requests that include malicious serialized payloads. Based on the description, it is inferred that exploitation would require authentication or write access to the plugin’s data, although this is not explicitly stated.
OpenCVE Enrichment
EUVD