Sceawere

Vulnerability Detail

CVE-2026-103349UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Object Injection in Product Feed PRO

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
2h ago
Vendor
Rymera Web Co
Product
Product Feed PRO for WooCommerce
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-05T19:17:13.703Z",
  "pubdate": "2026-10-05T19:17:13.703Z",
  "executiveSummary": "The Product Feed PRO for WooCommerce plugin is susceptible to a Deserialization of Untrusted Data vulnerability, categorized as an Object Injection flaw.\nThis vulnerability exists in versions from n/a through 13.5.7, allowing an unauthenticated or authenticated attacker to supply maliciously crafted serialized objects to the application.\nSuccessful exploitation enables arbitrary PHP object injection, which can lead to severe security compromises, including but not limited to Remote Code Execution (RCE), arbitrary file deletion, or sensitive data exfiltration, depending on the availability of 'gadget chains' within the application's codebase or bundled libraries.\nThe primary risk implication is a total compromise of the WordPress environment, as the deserialization process allows for the manipulation of application logic flow by leveraging existing class methods and properties.\nExploitation requires the attacker to reach a vulnerable entry point where user-controllable input is passed into an unsafe deserialization function, such as unserialize().\nOrganizations using the affected versions are at high risk, and immediate remediation is advised to prevent potential exploitation of the application server.",
  "technicalDetails": "The vulnerability resides in the improper handling of user-supplied data that is subsequently processed by PHP's unserialize() function without adequate validation or sanitization.\nDeserialization occurs when the application converts a stored or transmitted string back into a PHP object. When this data is sourced from an untrusted user input, an attacker can define the properties and the class type of the resulting object.\nThe root cause is the reliance on insecure deserialization of input streams that originate from external parameters. In PHP, the unserialize() function triggers the instantiation of objects and can automatically invoke 'magic methods' such as __wakeup(), __destruct(), or __toString() upon the object's creation or destruction.\nAn attacker exploits this by constructing a malicious serialized payload containing a serialized object chain—commonly referred to as a 'gadget chain'. This chain leverages existing classes within the WooCommerce environment or the plugin's own codebase to perform unintended actions.\nThe attack flow proceeds as follows: First, the attacker identifies a reachable input vector where the application accepts serialized data. Second, the attacker crafts a payload that instantiates a specific class available within the application's execution context. Third, the attacker manipulates the object's properties to redirect execution flow or trigger sensitive logic.\nIf a suitable gadget chain is present, the attacker can achieve Remote Code Execution by chaining together methods that lead to system-level commands, file operations, or database queries. Because these operations are executed under the context of the web server process (e.g., www-data), the attacker inherits the web server's privileges.\nThe vulnerability is present in versions 13.5.7 and prior. No specific authentication is inherently required if the vulnerable entry point is exposed to the public internet, as is common with many WooCommerce plugin hooks and AJAX handlers.\nPost-exploitation impact includes persistent backdoor installation, full access to the WooCommerce database containing sensitive customer information, and the ability to pivot into the underlying server infrastructure or lateral movement within the hosting environment."
}
CVE-2026-103349: Object Injection in Product Feed PRO (HIGH Severity, CVSS: 7.2) | Sceawere