Impact
The an unauthenticated PHP Object Injection flaw that permits attackers to supply a crafted serialized payload. When this data is deserialized without proper validation, the plugin can execute arbitrary PHP code on the host, enabling full compromise of the site’s confidentiality, integrity, and availability. The weakness corresponds to CWE‑502, which describes improper handling of serialized data.
Affected Systems
Any WordPress site that incorporates the Masteriyo – LMS plugin at version 3.4.0 or earlier is affected. The CVE targets only the plugin’s deserialization routine and does not affect other plugins or core WordPress versions.
Risk and Exploitability
The CVSS score of 8.8 marks this vulnerability as high severity, while the EPSS score of less than 1% indicates a low current exploitation probability. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is that an attacker can exploit the flaw by using unauthenticated access to a publicly reachable plugin endpoint and submitting malicious serialized data that the plugin then deserializes, potentially leading to arbitrary PHP code execution.
OpenCVE Enrichment