Impact
The vulnerability arises from the MainWP Child plugin’s handling of untrusted serialized data, which permits object injection. An attacker who can supply crafted payloads to the plugin can instantiate arbitrary PHP objects, potentially leading to arbitrary code execution, data leakage, or defacement. This flaw is classified under CWE-502, indicating that input validation during deserialization is insufficient. The primary impact is a compromise of the WordPress site hosting the plugin, affecting confidentiality, integrity, and availability of site data and functions.
Affected Systems
The affected product is the MainWP Child WordPress plugin up to and including version 6.2.1. Users running MainWP Child 6.2.1 or earlier should update to 6.2.2 or later, as this version removes the flawed deserialization logic. All WordPress sites that rely on this plugin are at risk, regardless of the overall WordPress version.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity rating. While the EPSS score is not available, the lack of an EPSS value does not diminish the inherent risk; the flaw enables arbitrary code execution with moderate complexity. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in known attacks. The attack vector is inferred to be remote, exploiting the plugin’s exposure to external or internal data sources such as HTTP requests or REST API endpoints. Given the serious nature of the flaw and the availability of a patch, the risk of exploitation remains significant if the plugin is not updated.
OpenCVE Enrichment