Impact
Export User Data, a WordPress plugin by QStudio, contains a PHP Object Injection flaw in all releases up to and including 2.2.6. This weakness allows an attacker to supply specially crafted serialized objects to the plugin’s processing routines, potentially leading to arbitrary code execution and full compromise of the affected WordPress site.
Affected Systems
The flaw applies to QStudio’s Export User Data plugin for WordPress versions up to 2.2.6. Any WordPress installation using this plugin, regardless of the WordPress core version, is vulnerable unless the plugin has been updated beyond 2.2.6.
Risk and Exploitability
The CVSS base score of 9.8 classifies the vulnerability as Critical, indicating maximum impact on confidentiality, integrity, and availability. EPSS data is not available, and the vulnerability has not been documented in CISA's KEV catalog. While the official description does not specify an attack vector, the nature of PHP Object Injection suggests that a remote attacker could exploit it over the web by sending crafted input to the plugin's endpoints.
OpenCVE Enrichment