Impact
The vulnerability is a PHP Object Injection flaw present in the Fluent Boards Pro plugin for WordPress versions up to 2.0.11. An attacker who can supply crafted serialized data can instantiate arbitrary PHP objects, leading to remote code execution on the affected server. The impact is the compromise of the entire web application, allowing the attacker to read, modify or delete any data, or take full control of the host.
Affected Systems
The flaw affects the WordPress plugin Fluent Boards Pro sold by WP Manage Ninja. Any WordPress site using version 2.0.11 or earlier of the plugin is vulnerable. Sites that host the plugin and expose its editor interface are at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. The EPSS score is not available, but the absence of a KEV listing suggests no widely known exploits at this time. The likely attack vector is remote via HTTP requests that deliver malformed serialized data through the plugin API or editor. Because the flaw can be triggered from external input, the risk of exploitation remains significant, especially on publicly accessible sites.
OpenCVE Enrichment