Impact
The Aitasi Coming Soon WordPress plugin performs deserialization of data from untrusted sources, which allows an attacker to craft payloads that cause object injection. This flaw, identified as CWE‑502, can lead to malicious code being executed on the host server if the plugin processes the crafted input. The impact includes possible compromise of website confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects the Aitasi Coming Soon plugin developed by Rubel Miah. Any installation of the plugin with version 2.0.2 or earlier is susceptible. Versions newer than 2.0.2 are not affected.
Risk and Exploitability
The CVSS score of 7.2 classifies this as a medium‑to‑high severity flaw, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Although the exact attack vector is not detailed in the CVE description, deserialization vulnerabilities typically require input delivery—such as a crafted HTTP request or maliciously stored configuration data—to trigger the flaw, suggesting that attackers might leverage the plugin’s data processing paths to inject malicious objects.
OpenCVE Enrichment
EUVD