Impact
The vulnerability is a Deserialization of Untrusted Data flaw that permits PHP Object Injection. By injecting crafted serialized objects into the plugin’s processing flow, an attacker can write arbitrary code to the server, potentially taking full control of the application. The weakness is identified as CWE‑502, which highlights the risks of improper handling of serialized data.
Affected Systems
The defect exists in the WordPress WP Spell Check plugin, affecting all versions from the initial release up to and including 12.1. No specific sub‑version list is provided, but the issue applies to every iteration before version 12.2.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. Although the EPSS score is not available, the absence of a listing in the CISA KEV catalog suggests no known large‑scale exploitation yet, but the potential for remote code execution remains. The attack likely requires sending specially crafted serialized data to a plugin endpoint that processes user input. Based on the description, it is inferred that the plugin accepts untrusted data via standard HTTP requests, making remote exploitation possible.
OpenCVE Enrichment