Impact
Unauthenticated PHP Object Injection has been identified in the Booster for WooCommerce plugin through version 8.4.0, allowing an attacker to instantiate arbitrary PHP objects. This flaw is classified as CWE-502 and can serve as a vector for remote code execution, potentially leading to full compromise of the affected WordPress site.
Affected Systems
The vulnerability affects installations of the Booster for WooCommerce plugin provided by Pluggabl. All releases up to and including version 8.4.0 are impacted. Users should verify their plugin version and plan to upgrade to at least version 8.5.0.
Risk and Exploitability
The CVSS score of 9.8 labels this flaw as critical. Although an EPSS score is not available, the lack of authentication required for exploitation and the high severity suggest a high likelihood of active exploitation attempts. The vulnerability is not listed in the CISA KEV catalog, but its critical CVSS rating and PHP Object Injection nature warrant a proactive response. Attackers can exploit the flaw by sending crafted input to endpoints processed by the plugin, creating malicious objects that can execute arbitrary code.
OpenCVE Enrichment