Impact
The flaw is an unauthenticated PHP Object Injection (CWE-502) in the FundEngine plugin for WordPress, affecting all releases up to and including 1.7.9. The inability to restrict input to benign serialized objects permits an attacker to submit malicious payloads that, when deserialized by the plugin, can trigger arbitrary code execution on the host. Based on the description, it is inferred that this leads to a total loss of confidentiality, integrity, and availability of the affected WordPress installation.
Affected Systems
Installations that employ the WordPress FundEngine plugin delivered by Roxnor with version numbers 1.7.9 or earlier. The plugin is typically used as part of WordPress fundraising or donation functionality.
Risk and Exploitability
The CVSS score of 9.8 reflects the high severity of the flaw. The EPSS score is not available, so the precise exploit probability is unknown; however, the vulnerability is unauthenticated and, based on the description, it is inferred that it can be exploited via standard HTTP requests, making the attack vector remote and straightforward once the plugin is installed. The plugin is not listed in the CISA KEV catalog, but its severity suggests active exploitation could be possible.
OpenCVE Enrichment