Impact
The vulnerability allows an attacker to inject malicious PHP objects through deserialization of untrusted data. By sending a crafted serialized object, the attacker can manipulate internal state and potentially execute arbitrary code on the infected server. This flaw is a classic deserialization weakness that compromises confidentiality, integrity, and availability of the WordPress site running the plugin.
Affected Systems
Smackcoders Inc. WP Ultimate Exporter plugin versions up to and including 3.0 are affected. Any WordPress site that has this plugin installed without updating to version 3.1 or newer is susceptible.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. The EPSS score is not provided, so no concrete exploitation probability can be derived from that metric. The vulnerability is not listed in the CISA KEV catalog. Likely attack vector is a remote attacker manipulating deserialization via the plugin’s input points, such as form submissions or API calls. Exploitation would require sending a crafted payload that the plugin inadvertently processes without validation.
OpenCVE Enrichment