Description
Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a through <= 1.5.4.
Published: 2025-04-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a PHP Object Injection that arises from deserializing untrusted data, classified as CWE-502. This flaw can allow a malicious actor to execute arbitrary PHP code, potentially compromising the entire site. The primary impact is remote code execution, allowing the attacker to read, modify, or delete site data and compromise confidentiality, integrity, and availability.

Affected Systems

The affected product is the GNUCommerce plugin for WordPress, developed by kagla, from unknown initial versions through version 1.5.4. All installations running these versions are vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, and the EPSS score of less than 1% signals a low-but-non-zero likelihood of exploitation. Based on the description, it is inferred that the flaw could be triggered by submitting a crafted object payload via any plugin endpoint that deserializes user input. While the vulnerability is not currently listed in the CISA KEV catalog, the high severity and potential for remote code execution warrant prompt action.

Generated by OpenCVE AI on May 2, 2026 at 02:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GNUCommerce plugin to a version newer than 1.5.4 as soon as possible.
  • If an upgrade cannot be applied immediately, disable or remove the plugin from the WordPress installation to block the attack surface.
  • As an interim precaution, enforce strict input validation and sanitization to ensure that no untrusted data is passed to PHP’s deserialization functions.
  • Monitor web server logs for suspicious object payloads or unexpected behavior that may indicate an attempt to exploit the flaw.

Generated by OpenCVE AI on May 2, 2026 at 02:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10944 Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection. This issue affects GNUCommerce: from n/a through 1.5.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection. This issue affects GNUCommerce: from n/a through 1.5.4. Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a through <= 1.5.4.
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 15 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Apr 2025 12:15:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection. This issue affects GNUCommerce: from n/a through 1.5.4.
Title WordPress GNUCommerce plugin <= 1.5.4 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:02.914Z

Reserved: 2025-03-26T09:22:41.972Z

Link: CVE-2025-30985

cve-icon Vulnrichment

Updated: 2025-04-15T13:31:49.755Z

cve-icon NVD

Status : Deferred

Published: 2025-04-15T12:15:22.463

Modified: 2026-04-23T15:27:27.510

Link: CVE-2025-30985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T02:30:25Z

Weaknesses