WordPress security changelog
CRITICAL CVE-2024-5335 Analyzed

Ultimate Store Kit: Code execution

Ultimate Store Kit is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.

CVE / CNA score 9.8 CVSS 3.1 · security@wordfence.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
Ultimate Store Kit
Plugin slug
ultimate-store-kit
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Aug 21, 2024
Weakness
CWE-502 — Deserialization of Untrusted Data

This CVE was published Aug 21, 2024 and is one of 14 known issues for this plugin.

Patch or disable the affected component.

Update Ultimate Store Kit to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_compare_products cookie in versions up to , and including, 1.6.4. This makes it possible for an unauthenticated attacker to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker or above to delete arbitrary files, retrieve sensitive data, or execute code.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Primary and upstream sources