Impact
Unauthenticated PHP Object Injection vulnerability is present in Payever – WooCommerce Gateway plugin versions up to 4.8.2. The flaw allows an attacker to instantiate arbitrary PHP objects without authentication and execute arbitrary code within the WordPress environment. This can compromise the confidentiality, integrity, and availability of the host system, as illustrated by CWE‑502. The likely attack vector is sending a crafted serialized payload to the plugin’s entry point, though the exact endpoint is not specified and is inferred from typical object injection patterns.
Affected Systems
The affected product is Payever – WooCommerce Gateway for WordPress. All installations running version 4.8.2 or earlier are vulnerable; newer releases are not affected.
Risk and Exploitability
The CVSS score of 9.8 reflects the high severity of this vulnerability. Although EPSS is not available and the issue is not listed in CISA KEV catalog, the lack of authentication requirement and the likely high potential for automated exploitation in the WordPress ecosystem suggest a significant risk. Based on the description, the likely attack vector is delivering a crafted request to the plugin’s entry point, creating malicious objects that lead to remote code execution.
OpenCVE Enrichment