Sceawere

Vulnerability Detail

CVE-2026-93651UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Minimum Maximum Quantity Object Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Dotstore
Product
Minimum and Maximum Quantity for WooCommerce
Attack Type
CWE-502 Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-30T13:17:22.543Z",
  "pubdate": "2026-09-30T13:17:22.543Z",
  "executiveSummary": "The Minimum and Maximum Quantity for WooCommerce plugin (versions 2.1.2 and below) contains a critical PHP Object Injection vulnerability.\nThis vulnerability stems from insecure deserialization of user-supplied input, allowing unauthenticated or low-privileged attackers to pass arbitrary serialized objects to the application.\nSuccessful exploitation enables remote code execution (RCE), arbitrary file deletion, or sensitive data exposure, depending on the available PHP gadgets within the WordPress environment.\nThe vulnerability poses a severe risk to the integrity and confidentiality of the entire WordPress installation.\nAttackers can leverage this flaw to gain full control over the web server by manipulating the application's object state via the injection of malicious serialized data payloads.",
  "technicalDetails": "The vulnerability exists due to the improper handling of serialized data passed via input parameters processed by the plugin. Specifically, the plugin employs the PHP unserialize() function on unsanitized user input without appropriate validation or object-type white-listing.\nWhen the application deserializes a crafted payload, it instantiates objects from classes defined within the scope of the plugin or the broader WordPress environment. If a 'POP' (Property-Oriented Programming) chain exists—which is common in complex plugins or themes—an attacker can leverage existing 'magic methods' (such as __destruct(), __wakeup(), or __toString()) to trigger unintended operations.\nThe attack flow begins with the attacker identifying an input vector, such as a GET or POST parameter, that the plugin transmits to an vulnerable unserialization sink. The attacker crafts a malicious serialized payload containing a chain of object definitions designed to manipulate application logic upon destruction or wake-up.\nOnce the payload is transmitted, the server-side script executes the unserialization process. If the attacker targets a gadget chain that modifies application state, they could theoretically override configuration objects, manipulate database queries, or trigger system calls if the chain supports file system interactions.\nThe vulnerability is restricted to versions <= 2.1.2. Because this is a PHP Object Injection issue, the impact is highly dependent on the presence of vulnerable classes (gadgets) within the plugin, the WooCommerce core, or the active WordPress theme. The presence of common libraries or large plugin ecosystems significantly increases the probability of identifying an exploitable gadget chain.\nAuthentication requirements depend on the specific entry point discovered in the plugin; however, many such vulnerabilities in WordPress plugins are reachable by unauthenticated attackers if the vulnerable function is hooked into an 'init' or 'admin_init' action that lacks capability checks.\nPost-exploitation, an attacker can achieve remote code execution, inject malicious administrative users, or exfiltrate sensitive site configuration data stored in the database. This represents a complete compromise of the application layer."
}
CVE-2026-93651: Minimum Maximum Quantity Object Injection (HIGH Severity, CVSS: 7.2) | Sceawere