What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in muzaara Muzaara Google Ads Report muzaara-adwords-optimize-dashboard allows Object Injection.This issue affects Muzaara Google Ads Report: from n/a through <= 3.1.
Explanation of Vulnerability in Simple Terms
02Summary
Muzaara Google Ads Report versions 3.1 and earlier contain a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code on the server. The vulnerability exists because the plugin deserializes untrusted data without proper validation. An attacker can exploit this remotely over the network without requiring user interaction or authentication.
What an attacker can do
03Attacker Capabilities
Run arbitrary code on the server and take complete control of the site.
Potential impact on your site
04Site Impact
Complete site compromise, data theft, malware installation, and potential lateral movement to other systems.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
January 22, 2025
CVE published
May 12, 2026
Record updated