Description
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
Published: 2026-09-12
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via PHP Object Injection
Action: Immediate Patch
AI Analysis

Impact

The wpstorecart WordPress plugin version 5.0.7 and earlier allows unauthenticated access to a bundled add‑on script that blindly deserializes user‑supplied data without restricting the classes that may be instantiated. By sending a crafted serialized payload to this endpoint, an attacker can inject a compatible gadget chain, which can be leveraged to achieve remote code execution or elevate privileges. This flaw is a classic case of PHP Object Injection and is classified as Deserialization of Untrusted Data.

Affected Systems

All WordPress installations that have the wpstorecart plugin at version 5.0.7 or earlier are affected. The vulnerability resides in the bundled wpsc‑membership‑pro paypal.php file, so any site that has not updated the plugin or removed the add‑on is at risk.

Risk and Exploitability

The vulnerability can be exploited over HTTP without authentication, making it highly attractive to attackers. The CVSS score of 8.1 indicates a high severity. The EPSS score is less than 1%, suggesting a low probability of exploitation. It is not listed in the CISA KEV catalog, so no known exploits are currently available. The absence of class restrictions on deserialization allows any gadget chain present on the site to be leveraged, potentially leading to remote code execution or privilege escalation.

Generated by OpenCVE AI on September 15, 2026 at 18:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the wpstorecart plugin to any release newer than 5.0.7; the newer releases contain the deserialization fix.
  • If an immediate update is not possible, block or remove access to the wpsc‑membership‑pro/paypal.php file using .htaccess, web server configuration, or a firewall rule to deny all non‑admin requests.
  • Configure PHP or an application firewall to enforce a whitelist of allowed classes during unserialize, or wrap the unserialize call in a strict check that rejects unaudited payloads.

Generated by OpenCVE AI on September 15, 2026 at 18:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
Title IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:31:26.861Z

Reserved: 2026-09-01T06:59:49.432Z

Link: CVE-2026-84099

cve-icon Vulnrichment

Updated: 2026-09-12T15:19:06.486Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:27.020

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-84099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data