Impact
This vulnerability is a PHP Object Injection flaw that occurs when untrusted serialized data is processed by the Icegram WordPress plugin. The flaw can be exploited to instantiate arbitrary PHP objects and execute code on the web server, leading to full compromise of the affected WordPress installation.
Affected Systems
The issue affects the Icegram WordPress plugin, version 3.1.31 or earlier. WordPress sites that use this plugin before updating to at least 3.1.44 are susceptible. No other vendors or versions are reported as affected.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. The EPSS score is not available, but the lack of a KEV listing does not diminish the high potential for exploitation, especially for attackers who can supply crafted serialized payloads via HTTP requests. Successful exploitation would provide an attacker with remote code execution on the server hosting the WordPress site.
OpenCVE Enrichment