Sceawere
Vulnerability Detail
CVE-2026-103349UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Object Injection in Product Feed PRO
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2h ago
- Vendor
- Rymera Web Co
- Product
- Product Feed PRO for WooCommerce
- Attack Type
- Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-05T19:17:13.703Z",
"pubdate": "2026-10-05T19:17:13.703Z",
"executiveSummary": "The Product Feed PRO for WooCommerce plugin is susceptible to a Deserialization of Untrusted Data vulnerability, categorized as an Object Injection flaw.\nThis vulnerability exists in versions from n/a through 13.5.7, allowing an unauthenticated or authenticated attacker to supply maliciously crafted serialized objects to the application.\nSuccessful exploitation enables arbitrary PHP object injection, which can lead to severe security compromises, including but not limited to Remote Code Execution (RCE), arbitrary file deletion, or sensitive data exfiltration, depending on the availability of 'gadget chains' within the application's codebase or bundled libraries.\nThe primary risk implication is a total compromise of the WordPress environment, as the deserialization process allows for the manipulation of application logic flow by leveraging existing class methods and properties.\nExploitation requires the attacker to reach a vulnerable entry point where user-controllable input is passed into an unsafe deserialization function, such as unserialize().\nOrganizations using the affected versions are at high risk, and immediate remediation is advised to prevent potential exploitation of the application server.",
"technicalDetails": "The vulnerability resides in the improper handling of user-supplied data that is subsequently processed by PHP's unserialize() function without adequate validation or sanitization.\nDeserialization occurs when the application converts a stored or transmitted string back into a PHP object. When this data is sourced from an untrusted user input, an attacker can define the properties and the class type of the resulting object.\nThe root cause is the reliance on insecure deserialization of input streams that originate from external parameters. In PHP, the unserialize() function triggers the instantiation of objects and can automatically invoke 'magic methods' such as __wakeup(), __destruct(), or __toString() upon the object's creation or destruction.\nAn attacker exploits this by constructing a malicious serialized payload containing a serialized object chain—commonly referred to as a 'gadget chain'. This chain leverages existing classes within the WooCommerce environment or the plugin's own codebase to perform unintended actions.\nThe attack flow proceeds as follows: First, the attacker identifies a reachable input vector where the application accepts serialized data. Second, the attacker crafts a payload that instantiates a specific class available within the application's execution context. Third, the attacker manipulates the object's properties to redirect execution flow or trigger sensitive logic.\nIf a suitable gadget chain is present, the attacker can achieve Remote Code Execution by chaining together methods that lead to system-level commands, file operations, or database queries. Because these operations are executed under the context of the web server process (e.g., www-data), the attacker inherits the web server's privileges.\nThe vulnerability is present in versions 13.5.7 and prior. No specific authentication is inherently required if the vulnerable entry point is exposed to the public internet, as is common with many WooCommerce plugin hooks and AJAX handlers.\nPost-exploitation impact includes persistent backdoor installation, full access to the WooCommerce database containing sensitive customer information, and the ability to pivot into the underlying server infrastructure or lateral movement within the hosting environment."
}