Impact
The vulnerability is a deserialization of untrusted data that allows PHP object injection within the VillaTheme AFFI – Affiliate Marketing for WooCommerce plugin. An attacker who can influence the serialized payload can construct arbitrary PHP objects, potentially leading to arbitrary code execution or manipulation of application data. The associated weakness is identified as CWE‑502, which signifies improper deserialization of untrusted data, a high‑risk class of vulnerability.
Affected Systems
VillaTheme’s AFFI – Affiliate Marketing for WooCommerce plugin, versions up to and including 1.0.10, is affected. WordPress sites that have installed such versions of the plugin are vulnerable.
Risk and Exploitability
With a CVSS score of 9.8, the severity reaches critical. The EPSS score is not available, but the lack of KEV listing suggests no reported exploitation yet. Nonetheless, the attack vector is likely remote, achieved through manipulated requests to the plugin’s endpoints, making the risk of exploitation significant for exposed WordPress installations.
OpenCVE Enrichment