Elementor Addons Vulnerable to PHP Object Injection via Deserialization
CVE-2024-8030
9.8CRITICAL
What is CVE-2024-8030?
The Ultimate Store Kit Elementor Addons, including various WooCommerce and EDD Builders, are susceptible to a PHP Object Injection flaw through the deserialization of untrusted input found in the _ultimate_store_kit_wishlist cookie. This vulnerability affects versions up to and including 2.0.3. Although the vulnerable plugin does not contain a PHP Object Pop chain, potential attackers could exploit an existing POP chain via other plugins or themes installed on the same system. This could lead to the capability for attackers to delete arbitrary files, access sensitive data, or execute arbitrary code on affected installations.
Affected Version(s)
Ultimate Store Kit β Addon For WooCommerce, EDD and Elementor 0 <= 2.0.3
