Impact
The vulnerability is an unauthenticated PHP Object Injection that allows an attacker to manipulate PHP serialization data processed by the Geo Controller plugin. If exploited, an attacker could execute arbitrary PHP code, compromise the WordPress site, and potentially take over the hosting environment. The weakness is classified as CWE-502, which denotes improper handling of serialized data leading to object injection.
Affected Systems
Vulnerable WordPress installations running the Geo Controller plugin version 8.9.8 or earlier. The affected vendor is INF.LENTUM FORM, producing the Geo Controller plugin.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. Because EPSS information is unavailable, the exact likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote and does not require authentication, meaning any user capable of submitting serialized data to the plugin endpoint could trigger the exploit. The high severity combined with the lack of authentication controls raises a substantial risk to site confidentiality, integrity, and availability.
OpenCVE Enrichment