Sceawere
Vulnerability Detail
CVE-2026-103348UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Ultimate Exporter Object Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 1h ago
- Vendor
- Smackcoders Inc.
- Product
- WP Ultimate Exporter
- Attack Type
- Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-05T20:17:08.330Z",
"pubdate": "2026-10-05T20:17:08.330Z",
"executiveSummary": "The WP Ultimate Exporter plugin for WordPress, developed by Smackcoders Inc., is susceptible to a deserialization of untrusted data vulnerability leading to PHP Object Injection.\nThis vulnerability exists in versions from n/a through 3.0, allowing unauthenticated or low-privileged remote attackers to inject serialized PHP objects into the application.\nThe primary risk involves the instantiation of arbitrary classes present within the application's scope, which can be leveraged to execute arbitrary code, manipulate sensitive data, or bypass security controls.\nSuccessful exploitation requires the attacker to submit crafted, malicious serialized payloads to vulnerable input vectors processed by the plugin.\nGiven the nature of object injection, this flaw poses a critical threat to server integrity, enabling potential remote code execution (RCE) if suitable 'POP' (Property Oriented Programming) chains exist within the environment.\nImpact includes complete site compromise, unauthorized database modifications, and potential lateral movement within the hosting infrastructure.",
"technicalDetails": "The vulnerability resides in the improper handling of user-supplied serialized data before passing it to PHP's unserialize() function. PHP Object Injection occurs when an application deserializes untrusted input without sufficient validation or integrity checks.\nIn the context of the WP Ultimate Exporter plugin, the vulnerability allows an attacker to control the properties of objects being instantiated. When the unserialize() function processes malicious input, it recreates an object based on the structure provided by the attacker.\nIf the application contains 'magic methods'—specifically __wakeup(), __destruct(), or __toString()—within the codebase or bundled dependencies, these methods are automatically triggered during or after the deserialization process.\nAttack flow typically involves the following stages: 1) Identification of an input vector that transmits serialized data to the server, often via GET/POST parameters or cookie values. 2) Creation of a malicious payload using a PHP script to generate a serialized object that matches a class existing in the target environment. 3) Inclusion of specific property values within the payload to influence the execution flow of the application's magic methods. 4) Delivery of the payload to the vulnerable endpoint. 5) Execution of the POP chain, where magic methods trigger subsequent function calls that lead to the attacker's desired outcome, such as file deletion, arbitrary database queries, or system command execution.\nBecause the vulnerability stems from the core functionality of how the plugin handles data exports/imports, it may be reachable over a network without requirement for elevated administrative privileges, depending on the specific endpoint exposed. Any existing class defined in the WordPress core, the plugin itself, or other installed third-party plugins can be leveraged as part of a POP chain, significantly increasing the attack surface.\nThe impact is not limited to the plugin's own scope; it is restricted only by the classes available in the execution environment at the time of the call. Consequently, this vulnerability represents a critical security risk for any WordPress site utilizing affected versions, as it provides a direct path to server-side exploitation through input manipulation."
}