CVE-2023-46615 MEDIUM

CVE-2023-46615: WordPress KD Coming Soon Plugin <= 1.7 is vulnerable to PHP Object Injection

Vendor Kalli Dan.
Product KD Coming Soon
Weakness CWE-502 · Unsafe deserialization
Published February 12, 2024
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.

Explanation of Vulnerability in Simple Terms

02Summary

KD Coming Soon versions up to 1.7 contain a deserialization flaw that allows an attacker to send malicious serialized data over the network. This can lead to unauthorized information disclosure or modification of site data. The attack requires specific conditions to succeed but does not require authentication or user interaction.

What an attacker can do

03Attacker Capabilities

Read or modify sensitive site data by sending crafted serialized objects to the application.

Potential impact on your site

04Site Impact

Unauthorized access to or modification of site data without requiring a user account or victim action.

Conditions required to exploit

05Prerequisites

Network access to the application; specific attack conditions must be met (high complexity).

Key dates

06Disclosure timeline

February 12, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE