CVE-2023-1549
The Ad Inserter plugin for WordPress through version 2.7.25 contains a PHP Object Injection vulnerability in its settings import functionality, where the $exported_settings variable undergoes unsafe deserialization of untrusted data. An authenticated user with administrative access can exploit this to inject arbitrary PHP objects, though the plugin itself lacks a Property-Oriented Programming chain necessary for exploitation. However, if additional plugins or themes on the same WordPress installation provide a usable POP chain, an attacker could leverage this vulnerability to execute arbitrary code, access sensitive information, or remove files from the server.
Based on public CVE data (MITRE/NVD).