Sceawere

Vulnerability Detail

CVE-2026-94568UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Object Injection in Pay with Vipps

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
WP Hosting AS
Product
Pay with Vipps for WooCommerce
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of Untrusted Data vulnerability in WP Hosting AS Pay with Vipps for WooCommerce woo-vipps allows Object Injection.This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-09T10:16:40.743Z",
  "pubdate": "2026-10-09T10:16:40.743Z",
  "executiveSummary": "The Pay with Vipps for WooCommerce plugin is susceptible to an Object Injection vulnerability resulting from the insecure deserialization of untrusted data.\nThis vulnerability allows an unauthenticated or low-privileged attacker to inject malicious serialized PHP objects into the application logic, potentially leading to arbitrary code execution, unauthorized file system access, or significant denial-of-service conditions.\nThe flaw affects all versions of the Pay with Vipps for WooCommerce plugin ranging from the initial release through version 6.2.0.\nThe risk is critical due to the potential for complete system compromise if suitable gadget chains are present within the environment.\nExploitation requires the attacker to submit crafted serialized data to an endpoint that passes the input directly into a PHP unserialize() function without sufficient validation or sanitation.\nOrganizations utilizing this plugin are at high risk, as successful exploitation bypasses standard authentication mechanisms to achieve remote code execution (RCE) in the context of the web server process.",
  "technicalDetails": "The vulnerability resides within the deserialization logic of the Pay with Vipps for WooCommerce plugin. In PHP, the unserialize() function converts a stored string representation of an object back into a PHP object instance. When an application calls this function on input provided by a user without implementing proper integrity checks, such as cryptographic signatures, it enables Object Injection.\nThe root cause is the handling of user-supplied data that is processed by unserialize(). By injecting a specially crafted serialized string, an attacker can instantiate arbitrary classes already defined within the WordPress environment, the active theme, or other installed plugins.\nThe primary mechanism of exploitation involves the utilization of 'POP chains' (Property Oriented Programming). An attacker identifies 'magic methods' (such as __destruct(), __wakeup(), or __toString()) within the application codebase that perform dangerous operations—like file deletion, database queries, or command execution—when triggered during the lifecycle of the reconstructed object.\nThe attack flow follows these steps: 1. The attacker identifies an entry point where user-controllable input is accepted and subsequently processed by an unserialize() call. 2. The attacker constructs a malicious payload consisting of a serialized PHP object structure that overrides existing object properties with malicious values. 3. The attacker transmits this payload via HTTP POST or GET parameters to the vulnerable endpoint. 4. Upon deserialization, the PHP engine instantiates the object, and the presence of malicious properties triggers the execution of magic methods. 5. If the application contains suitable gadget chains, the execution flow is diverted, allowing the attacker to execute arbitrary code or manipulate application states.\nSince the vulnerability exists within the plugin, the affected versions include all releases from inception up to and including 6.2.0. The vulnerability is typically exposed over the network, allowing remote attackers to trigger the flaw without the need for prior authentication, depending on the specific endpoint implementation. The impact of successful exploitation is severe, typically resulting in Remote Code Execution (RCE), which grants the attacker the ability to execute system-level commands, exfiltrate sensitive database information, or gain persistent access to the server infrastructure."
}
CVE-2026-94568: Object Injection in Pay with Vipps (HIGH Severity, CVSS: 7.2) | Sceawere