Impact
Unauthenticated PHP Object Injection is present in Wise Chat versions up to and including 3.4. The flaw allows arbitrary PHP objects to be unserialized from untrusted data, which can lead to the execution of attacker‑controlled code and compromise the entire WordPress site. The core weakness is the improper handling of serialized data (CWE-502), enabling a range of destructive actions such as data tampering, privilege escalation, data exfiltration, and site takeover.
Affected Systems
The affected product is the WordPress plugin Wise Chat from Marcin. Versions 3.4 and earlier are vulnerable. Site administrators running these versions of the plugin should immediately review their installation and plan remediation.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating high severity. The EPSS score is not currently available, and the vulnerability catalog. Based on the description, the likely attack vector is a web‑based request to the plugin’s endpoints that accepts serialized data. Because the flaw is unauth site could trigger the injection by crafting a malicious payload. Successful exploitation would allow an attacker to execute arbitrary PHP code with the permissions of the WordPress process, leading to full site compromise.
OpenCVE Enrichment