Impact
The vulnerability is a PHP Object Injection that can be triggered by a site administrator in any version of the Complianz plugin up to 7.5.0. When successfully exploited, an attacker can construct malicious PHP objects, leading to arbitrary code execution on the server. The weakness is identified as CWE‑502. An attacker with admin credentials could exploit this to take over the website, exfiltrate data, modify content, or install malware.
Affected Systems
Affected systems are WordPress sites using the Complianz GDPR plugin version 7.5.0 or earlier. The plugin is part of WordPress installations, and the vulnerability exists in all installations where the plugin has not been updated beyond that release. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS v3 score is 7.2, indicating a high severity but not critical. The EPSS score is less than 1%, suggesting low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. It likely requires the attacker to have or hijack administrative privileges within WordPress because the object injection can only occur through the plugin's back‑end interface. There is no public exploit yet, but the inherent risk of code execution makes it a priority for patching.
OpenCVE Enrichment