Ultimate Store Kit: Code execution
Ultimate Store Kit is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
- Component
- Ultimate Store Kit
- Plugin slug
ultimate-store-kit- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Aug 28, 2024
This CVE was published Aug 28, 2024 and is one of 14 known issues for this plugin.
Patch or disable the affected component.
Update Ultimate Store Kit to a release outside the affected range, or disable and remove it until a fixed version is available.
Technical description
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_wishlist cookie in versions up to , and including, 2.0.3. This makes it possible for an unauthenticated attacker to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker or above to delete arbitrary files, retrieve sensitive data, or execute code.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H