Impact
In the String locator WordPress plugin before 2.6.8, the database editor deserializes stored content without restricting permitted classes. This allows an unauthenticated user to save a crafted serialized PHP object, which is later instantiated by an administrator who edits and saves the row. The vulnerability is a classic deserialization flaw that can lead to arbitrary file deletion, sensitive data disclosure, or remote code execution if a suitable PHP Object‑oriented Programming chain exists within the same environment.
Affected Systems
Any WordPress site using the String locator plugin versions before 2.6.8 is affected. Later releases contain the fix and are not vulnerable. The vulnerability remains relevant for all prior releases of the plugin that have been publicly distributed via WordPress. No additional vendor or product information beyond the plugin name is available.
Risk and Exploitability
The CVSS score is not provided in the advisory, and no EPSS score is available, which limits formal risk quantification. The vulnerability is listed outside of CISA KEV, but the attack remains plausible because it can be triggered by anyone who can access the site’s database editor UI. Since the flaw requires an unauthenticated attacker to inject a serialized object, the primary attack vector is through unauthenticated web access to the database editor. Exploitation requires the presence of a PHP object chain in the same application or an additional vulnerable plugin that can be abused once the deserialized object is instantiated.
OpenCVE Enrichment