Impact
The CVE describes an unauthenticated PHP Object Injection flaw in the WPBruiser {no-Captcha anti-Spam} plugin up to version 3.1.43. The flaw allows an attacker to supply crafted serialized object data that PHP deserializes, enabling the creation of arbitrary object instances and potentially executing malicious code. As the vulnerability is unauthenticated, any visitor to the affected WordPress site can trigger it, giving an attacker full control over the web application and underlying server.
Affected Systems
The plugin is developed by MihChe and is part of WordPress installations that use the WPBruiser {no-Captcha anti-Spam} plugin. All instances of the plugin with a version equal to or earlier than 3.1.43 are affected. No specific additional software versions are listed; the issue applies to any site running the listed plugin without an updated version.
Risk and Exploitability
The CVSS score of 9.8 marks this as a critical flaw. Because the exploitation path is straightforward – a crafted HTTP request containing malicious serialized payload – the likelihood of exploitation is high, especially for sites that do not enforce strict input validation. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, but the severity indicates that attackers would likely target such sites early. As the flaw is unauthenticated, any user can carry out the attack.
OpenCVE Enrichment