Impact
An attacker can trigger PHP object injection by leveraging the deserialization of untrusted data in the ThemeMakers Visual Content Composer plugin. The flaw allows the creation of malicious objects that can manipulate internal state, leading to remote code execution, data theft, and system compromise. This directly violates confidentiality, integrity, and availability of the site.
Affected Systems
The affected vendor is ThemeMakers and the product is the ThemeMakers Visual Content Composer plugin, specifically all releases through version 1.5.8. No additional version range was specified beyond the installation maximum of 1.5.8.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. The EPSS score is reported as less than 1%, suggesting low current exploit probability, but the absence of a KEV listing does not mitigate the risk. Attackers can likely exploit the flaw remotely through any user‑containing serialized input accepted by the plugin. Although exploitation requires crafted serialized payloads, such inputs are often accessible via URL parameters, form fields, or API endpoints, making the attack vector network‑based.
OpenCVE Enrichment
EUVD