Impact
The vulnerability is a PHP Object Injection flaw affecting the Page Builder by SiteOrigin plugin for WordPress versions up to 2.36.0. An attacker who can supply crafted input to the editor can cause the plugin to unserialize untrusted data, leading to execution of arbitrary PHP code on the server. This grants full control over the affected WordPress site, allowing the attacker to modify content, install additional malware, or compromise the underlying server.
Affected Systems
The affected product is Greg – SiteOrigin Page Builder by SiteOrigin, a popular WordPress plugin used to design pages via a drag‑and‑drop interface. Any WordPress installation running a plugin version 2.36.0 or earlier is impacted. Versions 2.36.1 and later contain the patch.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity level. No EPSS score is available, so the current exploitation probability is unknown but the lack of public exploitation reports should not reduce the urgency. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to target sites with the vulnerable plugin by sending malicious requests to the editor endpoint, exploiting the unserialize call to inject malicious objects. No authentication requirement is explicitly stated, so the risk could affect both authenticated and unauthenticated users, but the exact prerequisites are not detailed.
OpenCVE Enrichment