Sceawere
Vulnerability Detail
CVE-2026-93771UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cost of Goods PHP Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- WPFactory
- Product
- Cost of Goods for WooCommerce
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-09-30T13:17:22.810Z",
"pubdate": "2026-09-30T13:17:22.810Z",
"executiveSummary": "The 'Cost of Goods for WooCommerce' plugin, versions <= 3.5.2, contains a critical PHP Object Injection vulnerability. This flaw allows an authenticated attacker with 'Shop Manager' privileges to inject arbitrary serialized PHP objects into the application. By manipulating these objects, an attacker can trigger unintended code execution paths, potentially leading to unauthorized data access, remote code execution (RCE), or server-side compromise. The vulnerability stems from the improper handling of user-supplied data during the deserialization process. This flaw poses a significant security risk, as it effectively bypasses standard authorization controls by leveraging the server's own deserialization mechanisms to instantiate arbitrary classes. Successful exploitation requires valid 'Shop Manager' authentication, but given the level of access associated with this role, the security implications for the WordPress environment are severe.",
"technicalDetails": "The vulnerability resides in the way the 'Cost of Goods for WooCommerce' plugin processes serialized data. In affected versions (<= 3.5.2), the plugin fails to properly validate or sanitize user input before passing it to the PHP unserialize() function. PHP Object Injection occurs when an attacker supplies a crafted serialized string to an application that expects to reconstruct a specific object type.\nThe attack flow begins when an authenticated user with 'Shop Manager' privileges interacts with a feature or endpoint that processes plugin-specific settings or metadata. By intercepting the HTTP request, an attacker can replace expected legitimate serialized data with a malicious payload. When the server-side code calls unserialize() on this input, it instantiates objects of classes that exist within the application's scope (including WordPress core and other installed plugins).\nThe core of the vulnerability is the potential for 'POP chains' (Property Oriented Programming). Even without direct execution functions, an attacker can leverage magic methods such as __wakeup(), __destruct(), or __toString() within existing, authorized classes to perform harmful operations. If the application environment contains 'gadget chains'—a sequence of magic methods and property states—an attacker can link these to achieve remote code execution, file system modification, or database manipulation.\nBecause the 'Shop Manager' role has inherent permissions to modify WooCommerce settings and product configurations, the attacker possesses the necessary prerequisites to reach the vulnerable code paths. This vulnerability is not exposed to unauthenticated users; however, the elevated privilege level of a 'Shop Manager' makes the exploit highly effective for internal threats or compromised manager accounts. Once the serialized payload is processed, the PHP interpreter recreates the object in memory with the attacker-specified property values. If these properties are later used in sensitive operations, the application's internal security logic is subverted.\nThe impact of a successful exploit is comprehensive. It allows for full control over the application's runtime environment, facilitating the bypassing of security controls, reading configuration files, or executing arbitrary system commands depending on the available PHP gadgets within the WordPress ecosystem. The vulnerability is restricted to environments where the plugin is active and the specific code path handling serialized user input is reached."
}