Impact
The vulnerability is a PHP Object Injection vulnerability caused by deserialization of untrusted data. Exploiting it could allow an attacker to create malicious PHP objects that are later unserialized by the plugin, potentially leading to remote code execution on the server. The flaw is identified as CWE‑502, which signals that insecure deserialization can compromise data integrity and confidentiality.
Affected Systems
The A WP Life:Modal Popup Box plugin, specifically the Modal Popup Box component, is affected in all versions up to and including 1.6.1. No other product or version information is supplied in the data.
Risk and Exploitability
This is a high severity flaw with a CVSS score of 8.8, indicating significant potential impact. The EPSS score is below 1%, suggesting that the exploitation likelihood is currently low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely an unauthenticated remote input that can be sent to the plugin’s data processing endpoint, though the exact method is not explicitly detailed.
OpenCVE Enrichment