Impact
The Events Manager plugin for WordPress deserializes input from untrusted sources, enabling PHP Object Injection in versions up to 7.3.6. According to CWE-502, this flaw can let an attacker execute arbitrary PHP code on the host, compromising the confidentiality, integrity, and availability of the affected site.
Affected Systems
All WordPress sites running the Events Manager plugin version 7.3.6 or earlier are affected. The vendor, Marcus (also known as @msykes), released the affected product, the Events Manager plugin, for all releases through 7.3.6.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of < 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector is a remote web request containing crafted serialized data that reaches the plugin's vulnerable deserialization routine.
OpenCVE Enrichment