Impact
An unauthenticated PHP Object Injection flaw exists in the GDPR Framework By Data443 plugin versions up to and including 2.5.0, allowing an attacker to create serialized objects that are deserialized by the plugin. The injection permits execution of arbitrary PHP code with the privileges of the web application, leading to full remote code execution. The flaw falls under CWE-502, reflecting an insecure deserialization vulnerability.
Affected Systems
The vulnerability affects WordPress sites that have the GDPR Framework By Data443 plugin installed. All releases of the plugin through version 2.5.0 are impacted. Site owners must identify whether they are running any of these vulnerable versions.
Risk and Exploitability
With a CVSS score of 9.8 and no EPSS or KEV information, the risk assessment indicates a highly severe condition. Because the flaw is unauthenticated and driven by crafted payloads, an attacker with internet connectivity to the site can exploit it without needing credentials. No public exploitation activity is recorded, but the lack of mitigations combined with the injection barrier makes exploitation highly likely if the vulnerability remains present.
OpenCVE Enrichment