Ultimate Store Kit Plugin Vulnerable to PHP Object Injection via Deserialization of Untrusted Input
CVE-2024-5335
What is CVE-2024-5335?
The Ultimate Store Kit Elementor Addons and its associated products are subject to a PHP Object Injection vulnerability, which arises from the deserialization of untrusted input found in the _ultimate_store_kit_compare_products cookie. This flaw is present in versions up to and including 1.6.4. An unauthenticated attacker can exploit this vulnerability to perform PHP Object Injection, potentially leading to unauthorized actions such as file deletion, sensitive data retrieval, or arbitrary code execution. While a proof of concept (POP) chain is not directly present in the vulnerable plugin, its presence through additional plugins or themes could enhance the severity of the attack.
Affected Version(s)
Ultimate Store Kit β Addon For WooCommerce, EDD and Elementor 0 <= 1.6.4
