Sceawere

Vulnerability Detail

CVE-2026-93624UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Music Player PHP Object Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
codepeople
Product
Music Player for WooCommerce
Attack Type
CWE-502 Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-30T13:17:22.407Z",
  "pubdate": "2026-09-30T13:17:22.407Z",
  "executiveSummary": "The Music Player for WooCommerce plugin, in versions 1.9.1 and below, contains a critical PHP Object Injection vulnerability. This vulnerability arises from the improper handling of user-supplied serialized data during the processing of plugin settings or requests.\nA Shop Manager or any user with equivalent privileges can leverage this flaw to instantiate arbitrary PHP objects within the application scope. This capability facilitates the execution of POP (Property-Oriented Programming) chains, which may lead to Remote Code Execution (RCE), unauthorized file manipulation, or sensitive data exposure.\nThe attack vector is remotely exploitable but requires authenticated access to the WooCommerce administrative backend or a specific interface interacting with the vulnerable component. Given the high-privilege requirement, the risk is categorized as significant for e-commerce platforms where shop managers may have a wider range of authorized users. Successful exploitation compromises the integrity, confidentiality, and availability of the WordPress installation and its underlying server environment.",
  "technicalDetails": "The vulnerability originates from the insecure utilization of the PHP 'unserialize()' function on unsanitized user input within the Music Player for WooCommerce plugin. In PHP, 'unserialize()' is inherently dangerous when processing data from untrusted sources, as it can be forced to instantiate objects of existing classes defined within the application or its loaded plugins.\nThe attack flow commences when the application processes a crafted HTTP request containing a serialized payload. An attacker, authenticated as a Shop Manager, intercepts or manually constructs a request targeting the vulnerable endpoint where plugin configuration parameters are submitted. By supplying a malicious serialized object, the attacker triggers the '__wakeup()' or '__destruct()' magic methods during the deserialization process.\nBy chaining these magic methods with existing classes present in the WordPress core, the plugin, or other installed themes/plugins, an attacker can construct a sophisticated POP chain. This chain allows for the manipulation of application state, such as overriding class properties to redirect execution flow or gain access to restricted administrative functionality.\nThe primary technical impact involves the ability to achieve Remote Code Execution (RCE) if the POP chain allows for the invocation of sensitive PHP functions like 'eval()', 'system()', or 'include()'. Furthermore, an attacker can influence the plugin's internal logic, potentially leading to unauthorized configuration changes, database modification, or cross-site scripting (XSS) if the object properties are reflected in the user interface.\nSince the affected versions (<= 1.9.1) do not implement adequate signature verification or input validation prior to deserialization, the attack surface remains open to anyone with the 'manage_woocommerce' or equivalent Shop Manager capabilities. Exploitation does not require direct access to the server's file system, as the attack is conducted entirely through the plugin's existing interface within the web application layer. Once the malicious object is successfully deserialized, the attacker gains the ability to execute code in the context of the web server process, potentially leading to full server compromise."
}
CVE-2026-93624: Music Player PHP Object Injection (HIGH Severity, CVSS: 7.2) | Sceawere