Impact
Deserialization of untrusted data in the bPlugins Super Video Player plugin can lead to PHP object injection. An attacker who can supply crafted serialized data may be able to create or manipulate objects, potentially allowing execution of arbitrary PHP code on the WordPress site. The vulnerability directly compromises the integrity and confidentiality of the application and could lead to full system compromise.
Affected Systems
The vulnerability affects the bPlugins Super Video Player WordPress plugin for all releases from the initial version through 1.8.13. Any WordPress installation using this plugin within that version range is impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates a high level of risk. EPSS information is not available, and the vulnerability is not listed in CISA KEV, so no publicly known exploit data is present. Based on the description, the likely attack vector involves an attacker supplying a malicious serialized payload to the plugin via an input field or URL parameter that is later deserialized without validation. This exploitation path requires the attacker to have access to the WordPress site’s file system or to supply input through form fields that are processed by the plugin, suggesting that the threat could be realized in a web‑based context if the plugin accepts external data.
OpenCVE Enrichment