Impact
The WP User Manager plugin for WordPress has a deserialization vulnerability that permits object injection via untrusted input. An attacker able to control the payload could deserialize crafted data, causing arbitrary code execution on the server. This weakness enables full compromise of the hosting environment, affecting confidentiality, integrity, and availability.
Affected Systems
The flaw is present in all releases of WP User Manager up to and including 2.9.12. The affected product is the WP User Manager WordPress plugin. Hosts running any of these versions are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of less than 1 % suggests a low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Though the attack vector is not explicitly stated in the advisory, the nature of the flaw implies exploitation via web requests to the plugin’s endpoints. An attacker with network or remote access to the site could inject malicious objects in a request, yielding remote code execution.
OpenCVE Enrichment