Sceawere
Vulnerability Detail
CVE-2026-93624UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Music Player PHP Object Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- codepeople
- Product
- Music Player for WooCommerce
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-09-30T13:17:22.407Z",
"pubdate": "2026-09-30T13:17:22.407Z",
"executiveSummary": "The Music Player for WooCommerce plugin, in versions 1.9.1 and below, contains a critical PHP Object Injection vulnerability. This vulnerability arises from the improper handling of user-supplied serialized data during the processing of plugin settings or requests.\nA Shop Manager or any user with equivalent privileges can leverage this flaw to instantiate arbitrary PHP objects within the application scope. This capability facilitates the execution of POP (Property-Oriented Programming) chains, which may lead to Remote Code Execution (RCE), unauthorized file manipulation, or sensitive data exposure.\nThe attack vector is remotely exploitable but requires authenticated access to the WooCommerce administrative backend or a specific interface interacting with the vulnerable component. Given the high-privilege requirement, the risk is categorized as significant for e-commerce platforms where shop managers may have a wider range of authorized users. Successful exploitation compromises the integrity, confidentiality, and availability of the WordPress installation and its underlying server environment.",
"technicalDetails": "The vulnerability originates from the insecure utilization of the PHP 'unserialize()' function on unsanitized user input within the Music Player for WooCommerce plugin. In PHP, 'unserialize()' is inherently dangerous when processing data from untrusted sources, as it can be forced to instantiate objects of existing classes defined within the application or its loaded plugins.\nThe attack flow commences when the application processes a crafted HTTP request containing a serialized payload. An attacker, authenticated as a Shop Manager, intercepts or manually constructs a request targeting the vulnerable endpoint where plugin configuration parameters are submitted. By supplying a malicious serialized object, the attacker triggers the '__wakeup()' or '__destruct()' magic methods during the deserialization process.\nBy chaining these magic methods with existing classes present in the WordPress core, the plugin, or other installed themes/plugins, an attacker can construct a sophisticated POP chain. This chain allows for the manipulation of application state, such as overriding class properties to redirect execution flow or gain access to restricted administrative functionality.\nThe primary technical impact involves the ability to achieve Remote Code Execution (RCE) if the POP chain allows for the invocation of sensitive PHP functions like 'eval()', 'system()', or 'include()'. Furthermore, an attacker can influence the plugin's internal logic, potentially leading to unauthorized configuration changes, database modification, or cross-site scripting (XSS) if the object properties are reflected in the user interface.\nSince the affected versions (<= 1.9.1) do not implement adequate signature verification or input validation prior to deserialization, the attack surface remains open to anyone with the 'manage_woocommerce' or equivalent Shop Manager capabilities. Exploitation does not require direct access to the server's file system, as the attack is conducted entirely through the plugin's existing interface within the web application layer. Once the malicious object is successfully deserialized, the attacker gains the ability to execute code in the context of the web server process, potentially leading to full server compromise."
}