PickPlugins Question Answer WordPress Plugin PHP Object Injection Vulnerability

Vulnerability

A PHP object injection vulnerability allowing object injection has been identified in the PickPlugins Question Answer WordPress plugin, affecting versions through 1.2.70. This vulnerability arises from the deserialization of untrusted data, which could potentially be exploited to execute arbitrary code, inject SQL, traverse directories, cause a denial-of-service, and more, if a suitable property-oriented programming chain is available.

Impact

Exploitation of this vulnerability could lead to PHP object injection, allowing for a range of attacks including code execution, SQL injection, path traversal, and denial-of-service, especially if a proper object-oriented programming chain is utilized.

Remediation

Users are advised to update to a version of the PickPlugins Question Answer WordPress plugin later than 1.2.70. For those unable to update immediately, Patchstack offers a virtual patch that can be applied to mitigate the vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.