Impact
Deserialization of untrusted data in YITH WooCommerce Affiliates versions up to 3.31.0 allows a PHP Object Injection flaw, classified as CWE‑502. An attacker can supply crafted serialized objects that the plugin unserializes, potentially leading to arbitrary code execution, data tampering, or disclosure. The vulnerability resides in the plugin’s handling of dynamic data during processing.
Affected Systems
The YITH WooCommerce Affiliates plugin for WordPress is affected. All installations using version 3.31.0 or earlier are vulnerable; versions 3.31.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.2 denotes moderate‑to‑high severity. No EPSS score is provided, so the current exploitation likelihood is unclear, but the lack of a KEV listing indicates no known widespread attacks yet. Attackers would need to supply malicious serialized data to the plugin, which could be delivered via crafted requests or input fields exposed by the plugin’s interface, potentially enabling remote code execution if successful.
OpenCVE Enrichment