Impact
Dynamic User Directory (<= 2.4) contains a PHP Object Injection flaw that is triggered via subscriber input. When special crafted serialized data is processed, an attacker can instantiate arbitrary PHP objects and execute code with the privileges of the web server. The vulnerability is a classic remote code execution vector originating from PHP deserialization mistakes.
Affected Systems
WordPress sites that have installed Dynamic User Directory plugin by Sarah Giles, on any version 2.4 or earlier. No other vendors or products were identified as affected.
Risk and Exploitability
The CVSS score of 9.8 shows this is a critical flaw. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the severity alone indicates a high risk. The likely attack vector is a remote HTTP request that submits crafted serialized input to the plugin; security controls that allow unauthenticated or low‑privilege posting can be abused. Given high severity, this flaw should be treated as a major threat if the plugin is in use.
OpenCVE Enrichment