Impact
This vulnerability arises from deserialization of untrusted input in the Dental Care CPT plugin, allowing attackers to inject arbitrary PHP objects. By manipulating serialized data, an attacker can trigger the execution of code within the WordPress environment, potentially compromising confidentiality, integrity, and availability of the site. The flaw is identified as CWE-502.
Affected Systems
The issue targets WordPress installations running the Dental Care CPT plugin from any version up to and including 20.2, distributed by strongholdthemes. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of <1% suggests a low probability of exploitation at present. The vulnerability is not yet listed in CISA KEV, but its potential for remote code execution makes it a priority. Based on the description, it is inferred that attackers could exploit the flaw by sending crafted serialized payloads to the plugin’s entry points, likely via harmless-looking HTTP requests, thereby gaining arbitrary code execution on the host.
OpenCVE Enrichment