Impact
The wpstorecart WordPress plugin version 5.0.7 and earlier allows unauthenticated access to a bundled add‑on script that blindly deserializes user‑supplied data without restricting the classes that may be instantiated. By sending a crafted serialized payload to this endpoint, an attacker can inject a compatible gadget chain, which can be leveraged to achieve remote code execution or elevate privileges. This flaw is a classic case of PHP Object Injection and is classified as Deserialization of Untrusted Data.
Affected Systems
All WordPress installations that have the wpstorecart plugin at version 5.0.7 or earlier are affected. The vulnerability resides in the bundled wpsc‑membership‑pro paypal.php file, so any site that has not updated the plugin or removed the add‑on is at risk.
Risk and Exploitability
The vulnerability can be exploited over HTTP without authentication, making it highly attractive to attackers. The CVSS score of 8.1 indicates a high severity. The EPSS score is less than 1%, suggesting a low probability of exploitation. It is not listed in the CISA KEV catalog, so no known exploits are currently available. The absence of class restrictions on deserialization allows any gadget chain present on the site to be leveraged, potentially leading to remote code execution or privilege escalation.
OpenCVE Enrichment