Impact
The vulnerability arises from the TranslatePress plugin’s handling of serialized data, allowing an attacker to inject crafted objects into the system. This flaw can lead to arbitrary code execution, compromising the confidentiality and integrity of the WordPress installation. The weakness corresponds to CWE‑502, which focuses on improper treatment of serialized data.
Affected Systems
The affected product is Cozmoslabs TranslatePress, specifically all releases up to and including version 2.10.2. Installations of these versions are vulnerable if the plugin is active and receives serialized input from external or administrative sources.
Risk and Exploitability
The CVSS score of 8.1 signals a high severity vulnerability, and the EPSS score of less than 1% indicates that widespread exploitation is unlikely at present. The flaw is not listed in the CISA KEV catalog. Though the attack vector is not explicitly described, it is inferred that an adversary could supply malicious serialized input through WordPress administrative or front‑end interfaces, leading to object injection and potential code execution.
OpenCVE Enrichment