Sceawere
Vulnerability Detail
CVE-2026-94568UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Object Injection in Pay with Vipps
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- WP Hosting AS
- Product
- Pay with Vipps for WooCommerce
- Attack Type
- Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Deserialization of Untrusted Data vulnerability in WP Hosting AS Pay with Vipps for WooCommerce woo-vipps allows Object Injection.This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-09T10:16:40.743Z",
"pubdate": "2026-10-09T10:16:40.743Z",
"executiveSummary": "The Pay with Vipps for WooCommerce plugin is susceptible to an Object Injection vulnerability resulting from the insecure deserialization of untrusted data.\nThis vulnerability allows an unauthenticated or low-privileged attacker to inject malicious serialized PHP objects into the application logic, potentially leading to arbitrary code execution, unauthorized file system access, or significant denial-of-service conditions.\nThe flaw affects all versions of the Pay with Vipps for WooCommerce plugin ranging from the initial release through version 6.2.0.\nThe risk is critical due to the potential for complete system compromise if suitable gadget chains are present within the environment.\nExploitation requires the attacker to submit crafted serialized data to an endpoint that passes the input directly into a PHP unserialize() function without sufficient validation or sanitation.\nOrganizations utilizing this plugin are at high risk, as successful exploitation bypasses standard authentication mechanisms to achieve remote code execution (RCE) in the context of the web server process.",
"technicalDetails": "The vulnerability resides within the deserialization logic of the Pay with Vipps for WooCommerce plugin. In PHP, the unserialize() function converts a stored string representation of an object back into a PHP object instance. When an application calls this function on input provided by a user without implementing proper integrity checks, such as cryptographic signatures, it enables Object Injection.\nThe root cause is the handling of user-supplied data that is processed by unserialize(). By injecting a specially crafted serialized string, an attacker can instantiate arbitrary classes already defined within the WordPress environment, the active theme, or other installed plugins.\nThe primary mechanism of exploitation involves the utilization of 'POP chains' (Property Oriented Programming). An attacker identifies 'magic methods' (such as __destruct(), __wakeup(), or __toString()) within the application codebase that perform dangerous operations—like file deletion, database queries, or command execution—when triggered during the lifecycle of the reconstructed object.\nThe attack flow follows these steps: 1. The attacker identifies an entry point where user-controllable input is accepted and subsequently processed by an unserialize() call. 2. The attacker constructs a malicious payload consisting of a serialized PHP object structure that overrides existing object properties with malicious values. 3. The attacker transmits this payload via HTTP POST or GET parameters to the vulnerable endpoint. 4. Upon deserialization, the PHP engine instantiates the object, and the presence of malicious properties triggers the execution of magic methods. 5. If the application contains suitable gadget chains, the execution flow is diverted, allowing the attacker to execute arbitrary code or manipulate application states.\nSince the vulnerability exists within the plugin, the affected versions include all releases from inception up to and including 6.2.0. The vulnerability is typically exposed over the network, allowing remote attackers to trigger the flaw without the need for prior authentication, depending on the specific endpoint implementation. The impact of successful exploitation is severe, typically resulting in Remote Code Execution (RCE), which grants the attacker the ability to execute system-level commands, exfiltrate sensitive database information, or gain persistent access to the server infrastructure."
}