Impact
Deserialization of untrusted data in the SUMO Affiliates Pro WordPress plugin enables PHP Object Injection, which can allow an attacker to execute arbitrary code on the affected server. The flaw carries a high severity with a CVSS score of 9.8 and is classified as CWE‑502, indicating deserialization vulnerabilities leading to object injection.
Affected Systems
The issue affects all releases of FantasticPlugins SUMO Affiliates Pro prior to version 11.4.0. Any site that has installed this plugin with a version earlier than 11.4.0 is vulnerable.
Risk and Exploitability
The public EPSS score is below 1%, suggesting that exploitation is not common in the wild, yet the high CVSS score signals severe potential damage. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Likely attack vectors involve the plugin’s web interface, where a malicious user could craft and submit a serialized payload to trigger the object injection.
OpenCVE Enrichment