Impact
The Turnkey bbPress by WeaverTheme plugin deserializes administrator‑uploaded file content without validation, creating a PHP Object Injection vulnerability. An attacker with administrator or higher privileges can craft malicious serialized data to inject arbitrary PHP objects, potentially leading to deletion of system files, retrieval of sensitive information, or code execution if a PHP Object Persistence (POP) chain is present in another plugin or theme. The plugin itself does not contain a POP chain, but the existence of a chain would allow the attacker to bypass this limitation.
Affected Systems
WordPress sites running Turnkey bbPress by WeaverTheme plugin version 1.7.1 or earlier are affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity. Exploitation requires authenticated accounts with administrator or higher privileges, limiting the attack surface. Because the vulnerability lacks an immediate POP chain, attackers must rely on additional vulnerable components to achieve code execution, raising the effort required. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, so no large‑scale exploitation is documented. Nonetheless, the potential impact of data loss or code execution warrants prompt remediation.
OpenCVE Enrichment