Sceawere

Vulnerability Detail

CVE-2026-94677UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kadence WooCommerce Email Designer Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Nexcess
Product
Kadence WooCommerce Email Designer
Attack Type
CWE-502 Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-30T13:17:27.540Z",
  "pubdate": "2026-09-30T13:17:27.540Z",
  "executiveSummary": "Kadence WooCommerce Email Designer versions 1.5.19.1 and below are susceptible to a PHP Object Injection vulnerability.\nThis security flaw allows an authenticated attacker with Shop Manager privileges to inject malicious serialized objects into the application.\nThe vulnerability arises from insecure deserialization of user-supplied input, which can be leveraged to achieve remote code execution (RCE) or perform other unauthorized actions.\nThe impact includes full compromise of the application context, potentially allowing the attacker to execute arbitrary code, manipulate system files, or access sensitive database information.\nThe exploitation requires the attacker to possess at least Shop Manager level privileges within the WordPress environment, limiting the initial attack surface to authenticated users with specific roles.\nRisk implications are high as the vulnerability facilitates unauthorized manipulation of application logic through POP (Property Oriented Programming) chains.\nSuccessful exploitation necessitates that the application environment contains reachable 'gadget chains' within the included codebase or active plugins that can be triggered upon the destruction or manipulation of the injected object.",
  "technicalDetails": "The vulnerability exists due to improper handling of user-controllable data that is passed into PHP's unserialize() function. In Kadence WooCommerce Email Designer, input vectors processed by the plugin fail to validate the structure and content of the serialized data before reconstruction.\nRoot Cause: The plugin architecture contains logic that accepts serialized strings provided by the user and passes them directly to the PHP unserialize() function. Because PHP's deserialization process can trigger magic methods such as __wakeup(), __destruct(), or __toString() on objects being instantiated, an attacker can craft a malicious serialized payload.\nExploitation Method: An attacker with Shop Manager privileges targets the vulnerable endpoint, supplying a specially crafted serialized object. This object is designed to interact with existing classes present in the application's memory space. By chaining these classes—a technique known as POP chain construction—the attacker can achieve unintended execution flow.\nAttack Flow: 1. The attacker authenticates as a Shop Manager. 2. The attacker identifies the vulnerable input parameter handled by the plugin. 3. The attacker submits a malicious serialized PHP object payload. 4. The application triggers the unserialize() function on this input. 5. The PHP engine instantiates the attacker-controlled object, triggering magic methods that reference existing gadget chains. 6. The gadget chain execution achieves the attacker's goal, such as calling sensitive functions (e.g., system(), exec(), or include()) or writing arbitrary files to the server.\nAffected Versions: Kadence WooCommerce Email Designer <= 1.5.19.1.\nAuthentication Requirements: This vulnerability requires the attacker to be authenticated as a user with the 'Shop Manager' role, which is typically capable of managing WooCommerce settings and shop configurations.\nPost-Exploitation Impact: Successful exploitation results in RCE, allowing the attacker to bypass access controls, escalate privileges further, exfiltrate data, or deploy persistent backdoors within the server environment. The impact is essentially total control over the site's application layer, limited only by the permissions of the web server user."
}
CVE-2026-94677: Kadence WooCommerce Email Designer Injection (HIGH Severity, CVSS: 7.2) | Sceawere