Impact
The flaw is an improper control of code generation that enables code injection. An attacker who can influence input processed by the Javo Core plugin can inject and execute arbitrary PHP code on the server. This results in full compromise of the WordPress site and the underlying infrastructure.
Affected Systems
The vulnerability exists in the Javo Core plugin from JavoThemes. All releases up through 3.0.0.266 are affected. The plugin runs on any WordPress installation that has been deployed with those versions, so any site that installed them is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of < 1% suggests a low probability of exploitation. The issue is not listed in CISA's KEV catalog. The likely attack vector is via HTTP requests that supply untrusted input to the plugin, such as form submissions or file uploads. If exploited, the attacker can run arbitrary code, compromising the entire site and potentially the server.
OpenCVE Enrichment