Description
Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Object Injection.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.4.0.
Published: 2025-04-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bug is a deserialization of untrusted data in the Ultimate Store Kit Elementor Addons plugin, identified as a CWE‑502 vulnerability. An attacker who can supply crafted serialized payloads to the plugin may trigger object injection, which can immediately lead to remote code execution and full compromise of the affected WordPress site. The flaw allows malicious code to run with the permissions of the WordPress installation, potentially exposing site data, defacing the site, or installing backdoors.

Affected Systems

WordPress sites running the bdthemes Ultimate Store Kit Elementor Addons plugin, versions from the earliest available release through 2.4.0, are affected. The vulnerability exists in any installation that has not upgraded beyond 2.4.0. No other products by bdthemes are known to be impacted, and there are no specific sub‑components listed as affected.

Risk and Exploitability

The CVSS score is 9.8, indicating critical severity. The EPSS score is under 1 %, so active exploitation is believed to be rare, and the vulnerability is not listed in CISA’s KEV catalog. The most probable attack vector is the deserialization of untrusted data provided by the plugin, likely through crafted HTTP requests or user uploads that the plugin processes. Because the flaw permits arbitrary code execution, a successful exploit would give an attacker full control over the affected WordPress installation.

Generated by OpenCVE AI on April 30, 2026 at 22:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Ultimate Store Kit Elementor Addons to the latest release (≥ 2.5.0).
  • If an upgrade cannot be performed immediately, deactivate the plugin to block the vulnerable code paths.
  • Continuously monitor site logs for abnormal deserialization attempts and apply web‑application firewall rules to reject suspicious payloads.

Generated by OpenCVE AI on April 30, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11757 Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Object Injection. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Object Injection. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0. Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Object Injection.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.4.0.
Title WordPress Ultimate Store Kit Elementor Addons <= 2.4.0 - Deserialization of untrusted data Vulnerability WordPress Ultimate Store Kit Elementor Addons plugin <= 2.4.0 - Deserialization of untrusted data Vulnerability
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Object Injection. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.
Title WordPress Ultimate Store Kit Elementor Addons <= 2.4.0 - Deserialization of untrusted data Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:35.203Z

Reserved: 2025-04-16T06:26:52.001Z

Link: CVE-2025-39588

cve-icon Vulnrichment

Updated: 2025-04-17T17:42:58.101Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:58.953

Modified: 2026-04-23T15:29:50.620

Link: CVE-2025-39588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:30:02Z

Weaknesses