Impact
The vulnerability is an unauthenticated deserialization flaw in versions of the WordPress Youzify plugin up to 1.3.7. Without proper input validation, the plugin will deserialize data from potentially untrusted sources, enabling an attacker to craft serialized payloads that instantiate arbitrary objects. This flaw aligns with CWE‑502 and can lead to remote code execution, allowing attackers to gain full control of the affected WordPress site.
Affected Systems
The affected software is the Youzify WordPress plugin for versions 1.3.7 and earlier, distributed by the vendor Youzify. Any WordPress installation that has this plugin installed is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 classifies the issue as critical, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available. Because the flaw is triggered by unauthenticated web requests processed by the plugin's code path, an attacker with internet access to the site may exploit it remotely. The lack of a current EPSS score and KEV listing does not diminish the high severity suggested by the CVSS score.
OpenCVE Enrichment