Impact
The vulnerability is a deserialization of untrusted data flaw in the strongholdthemes Tech Life CPT WordPress plugin that permits object injection. If an attacker can supply crafted data to the plugin, they can instantiate PHP objects unchecked, which may allow execution of malicious code and compromise the server or site. This threat carries the core weakness CWE-502 and can result in full code execution and control over the affected WordPress installation.
Affected Systems
Any WordPress site running any version of the Tech Life CPT plugin through version 16.4 is affected. The vulnerability is not limited to specific configurations, so all installations using older releases are at risk until they upgrade past 16.4.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity level, while the EPSS score of less than 1% suggests that exploitation attempts are currently rare, though not impossible. The vulnerability is not listed in CISA’s KEV catalog, meaning no known widespread exploitation has been documented. Attackers can exploit it by supplying malicious payloads during normal plugin operations, likely requiring authenticated or privileged access to the WordPress admin, but the details of the exact attack vector are not fully disclosed in the public description, so the exact prerequisites remain inferred.
OpenCVE Enrichment