Impact
The Simple Event Planner plugin deserializes untrusted input, enabling an object injection flaw. An attacker can craft malicious serialized data that, once processed, may instantiate arbitrary PHP objects and trigger code execution. This could give the attacker full control of the WordPress site, allowing data theft, defacement, or further compromise of the underlying server.
Affected Systems
PressTigers Simple Event Planner is impacted when installed at any version up to and including 1.5.7. Systems running WordPress with this plugin version are vulnerable. The problem does not appear in any later releases such as 1.5.8 or newer.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 8.8, placing it in the high‑severity range and implying that exploitation could lead to complete compromise. No EPSS score is supplied, and the issue is not listed in CISA’s KEV catalog, suggesting that large‑scale, publicly known exploitation may not yet have been observed. The attack vector is inferred to be remote, likely triggered by a crafted HTTP request or content submitted through the plugin’s interface.
OpenCVE Enrichment