Impact
The vulnerability in the Employee Directory – Staff Listing & Team Directory Plugin for WordPress allows an attacker to supply crafted serialized data that the plugin deserializes without validation. This deserialization flaw is a PHP Object Injection (CWE‑502) that can lead to arbitrary code execution on the server hosting the WordPress site, thereby compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The plugin, provided by emarket-design and named Employee Directory – Staff Listing & Team Directory Plugin for WordPress, is vulnerable in all releases from its earliest version up to and including 4.5.5. WordPress sites using this plugin with those version numbers are affected.
Risk and Exploitability
The CVSS score of 8.1 indicates a high impact vulnerability. Because the EPSS score is reported as < 1 %, the likelihood of discovery and exploitation is low at present, and the flaw is not yet listed in CISA’s KEV catalog. The likely attack vector is a remote web request to the plugin’s administrative or public endpoints, where the attacker can inject the malicious serialized payload. A successful exploitation would give the attacker the ability to execute arbitrary PHP code on the web server, exposing the entire WordPress installation.
OpenCVE Enrichment
EUVD