WooCommerce Product Carousel Slider & Grid Ultimate Vulnerable to PHP Object Injection
CVE-2024-1950
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 March 2024
What is CVE-2024-1950?
The Product Carousel Slider & Grid Ultimate for WooCommerce plugin in WordPress is susceptible to PHP Object Injection through the deserialization of untrusted input via shortcode. This vulnerability affects all versions up to and including 1.9.7. Authenticated attackers with contributor access or higher can exploit this flaw to inject malicious PHP objects. Without a Present Object Protocol (POP) chain within the plugin, the direct impact is limited. However, if additional plugins or themes are present that incorporate a POP chain, the attacker could potentially delete arbitrary files, access sensitive information, or execute harmful code.
Affected Version(s)
Product Carousel Slider & Grid Ultimate for WooCommerce * <= 1.9.7