Impact
The flaw is a PHP Object Injection vulnerability found in the WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin up to version 3.3.8. By manipulating serialized data submitted through the plugin’s input fields, an attacker can force PHP to deserialize crafted objects, allowing the injection of arbitrary code. Successful exploitation could give the attacker full control over the hosting environment, compromising confidentiality, integrity, and availability of the WordPress site and potentially the underlying server. The weakness is identified as CWE-502.
Affected Systems
ThemeHigh’s Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin versions 3.3.8 and earlier are affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. While explicit prerequisites are not detailed in the advisory, the likely attack path would involve sending a malicious payload through the plugin’s form interface, which requires authenticated access to the WordPress admin area. If the plugin exposes endpoints to unauthenticated users, the risk increases further, but the documented exploitation vector appears to be through administrative input processing.
OpenCVE Enrichment