Impact
EventPrime plugin versions up to 4.3.4.1 allow PHP Object Injection, a flaw where arbitrary PHP objects can be deserialized from untrusted input. The vulnerability is a CWE‑502 weakness that can enable attackers to execute arbitrary code, modify data, or gain elevated privileges once the plugin processes malicious serialized payloads.
Affected Systems
Any WordPress installation running the EventPrime plugin by EventPrime, in versions 4.3.4.1 or earlier.
Risk and Exploitability
The flaw scores 8.8 on CVSS, indicating high severity. No EPSS data is available, so exploitation likelihood cannot be quantified, and the vulnerability is not yet listed in CISA KEV. Based on the description, it is inferred that the attack vector involves an authenticated user with access to the subscriber component who can supply crafted serialized data to trigger the injection.
OpenCVE Enrichment