Sceawere
Vulnerability Detail
CVE-2026-42718UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated PHP Object Injection in Booster for WooCommerce
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 5h ago
- Vendor
- Pluggabl
- Product
- Booster for WooCommerce
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated PHP Object Injection in Booster for WooCommerce <= 8.4.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-10T20:16:36.907Z",
"pubdate": "2026-10-10T20:16:36.907Z",
"executiveSummary": "A critical security vulnerability identified as an unauthenticated PHP Object Injection exists in Booster for WooCommerce versions 8.4.0 and below.\nThis vulnerability allows remote, unauthenticated attackers to supply maliciously crafted serialized data to the application.\nUpon deserialization, this payload can facilitate arbitrary code execution, unauthorized file system access, or other malicious actions within the server environment.\nThe flaw resides in how the plugin handles user-supplied input before passing it to PHP's unserialize() function, bypassing the need for administrative or subscriber-level privileges.\nThe risk is severe as it provides an attacker with a high degree of control over the affected WordPress instance, potentially leading to a complete compromise of the web server, sensitive data exfiltration, or unauthorized administrative actions.\nSuccessful exploitation requires no prior authentication, making it an attractive target for automated exploit campaigns against vulnerable WooCommerce installations.",
"technicalDetails": "The vulnerability is rooted in the improper implementation of PHP's unserialize() function on untrusted, unauthenticated user input within the Booster for WooCommerce plugin.\nIn PHP, the unserialize() function is inherently dangerous when handling input from an external source because it allows the instantiation of objects from any classes currently defined within the application context.\nAn attacker can exploit this by crafting a serialized PHP object payload that triggers 'magic methods'—specifically __destruct(), __wakeup(), or __toString()—within existing classes available to the WordPress environment (including core files, themes, or other plugins).\nThe attack flow begins with the attacker identifying a publicly accessible endpoint or form field within the Booster for WooCommerce plugin that fails to validate or sanitize input before processing it via unserialize().\nOnce the target endpoint is identified, the attacker constructs a payload consisting of a serialized object chain known as a 'POP chain' (Property-Oriented Programming chain).\nThis chain leverages existing code 'gadgets'—class properties and methods—to influence the application flow. For instance, an attacker may overwrite object properties to bypass security checks or redirect execution to malicious code paths.\nBy manipulating the object state, the attacker can force the application to perform unauthorized actions such as arbitrary file deletion, modification of application configuration, or, in many cases, achieving Remote Code Execution (RCE) by leveraging gadgets that facilitate file writes or command execution.\nThe vulnerability is effective against all versions of Booster for WooCommerce <= 8.4.0. Because the injection point is reachable without any authentication, the attack surface is globally exposed to the internet.\nPost-exploitation, the attacker gains the execution context of the web server user. This often results in full system compromise, the installation of backdoors, or the lateral movement within the hosting environment if the server is improperly segmented.\nThe root cause is the reliance on user-controllable input for PHP deserialization, violating standard secure coding practices which mandate the use of safer data exchange formats like JSON when dealing with external input."
}