Impact
The Kalles Addons plugin for WordPress contains an unauthenticated PHP Object Injection flaw that allows attackers to instantiate arbitrary PHP objects and execute code, leading to remote code execution. This vulnerability is made possible by the plugin’s handling of PHP serialized data from user input without proper validation.
Affected Systems
Any WordPress installation that has the Kalles Addons plugin version 1.0.6 or earlier, provided by the vendor The4, is affected. The flaw applies to all sites that deploy those plugin versions, regardless of other configuration settings.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8, marking it as critical, and it is not listed in CISA’s KEV catalog. The EPSS score is < 1%, indicating a low but nonzero probability of exploitation. The attack likely occurs via unauthenticated web requests that supply malicious serialized payloads to the plugin; successful exploitation would grant an attacker full remote code execution on the affected server.
OpenCVE Enrichment