Impact
The ARMember Premium plugin for WordPress versions 7.0 and earlier contains a PHP Object Injection flaw (CWE‑502). When an attacker can supply crafted serialized data—typically through the contributor or editable content interface—the plugin’s unserialization routine executes that data, allowing arbitrary code to run on the server. This permits full compromise of the WordPress site, leading to loss of confidentiality, integrity, and availability. Based on the description, it is inferred that the attacker would need to send serialized data via the contributor or editable content interface; this inference is not explicitly stated in the official notes.
Affected Systems
Reputeinfosystems ARMember Premium plugin for WordPress. Versions 7.0 and earlier are affected. Any WordPress installation that has the plugin at these versions is at risk.
Risk and Exploitability
The CVSS base score of 8.8 classifies this issue as a high‑severity flaw. The EPSS score of less than 1% indicates a low probability of exploitation. The exploitation path relies on privileged contributor access or an attacker who can inject serialized data; once the malicious payload is processed, the attacker gains unrestricted control of the server. The likely attack vector involves a contributor or attacker data, which is inferred from the described unserialization logic.
OpenCVE Enrichment