Impact
The problem is a PHP Object Injection flaw that arises when untrusted user data is deserialized by the Sunshine Photo Cart plugin. An attacker can craft a malicious serialized payload that, when processed, triggers the creation of arbitrary PHP objects with malicious instructions. The result is that the attacker can execute arbitrary code on the WordPress site, compromising confidentiality, integrity, and availability of the entire system.
Affected Systems
The vulnerability exists in the WordPress Sunshine Sunshine Photo Cart plugin for all releases from the initial release up through version 3.7.1. Any WordPress installation that has one of those plugin versions installed is affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability. The exploit probability (EPSS) is not available, and the flaw is not listed in CISA’s KEV catalog, which does not rule out exploitation. Object injection is routinely used for remote code execution, so an attacker could exploit this weakness by supplying a malicious payload through any input that the plugin processes, such as form submissions or API calls. The resulting compromise could allow full control over the affected WordPress site.
OpenCVE Enrichment