Impact
The vulnerability is a PHP Object Injection flaw in the WordPress Nested Pages plugin that allows attackers to manipulate serialized data, leading to arbitrary code execution and full compromise of the affected WordPress site, including confidentiality, integrity, and availability.
Affected Systems
The affected products are the WordPress Nested Pages plugin by Hook & Filter for WordPress installations running version 3.3.2 or older; the plugin can be installed on any public WordPress site.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity, but the EPSS score is not available and the flaw is not listed in CISA KEV, indicating no publicly known active exploits at the time of analysis. The likely attack vector is remote, via crafted HTTP requests that trigger the unsanitized deserialization within the plugin; authentication is not required to exploit this vulnerability.
OpenCVE Enrichment