Sceawere
Vulnerability Detail
CVE-2026-94678UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Go Live Update Urls Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Mat Lipe
- Product
- Go Live Update Urls
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-30T13:17:27.673Z",
"pubdate": "2026-09-30T13:17:27.673Z",
"executiveSummary": "The Go Live Update Urls plugin for WordPress, specifically in versions 7.0.8 and earlier, is susceptible to a PHP Object Injection vulnerability.\nThis security flaw stems from the insecure deserialization of user-supplied input provided through specific plugin parameters.\nThe vulnerability allows an unauthenticated or authenticated attacker with minimal privileges to inject malicious serialized PHP objects into the application.\nBy manipulating these objects, an attacker can trigger unintended code execution, potentially leading to full site compromise, arbitrary file deletion, or unauthorized administrative actions.\nSuccessful exploitation requires the presence of 'gadget chains' within the application environment—sets of existing code segments that, when executed during the deserialization process, perform actions favorable to the attacker.\nThe risk is critical, as it bypasses standard input validation mechanisms, enabling an attacker to exert control over the server-side processing logic.\nImpact includes potential Remote Code Execution (RCE) and complete loss of confidentiality, integrity, and availability of the affected WordPress instance.",
"technicalDetails": "The vulnerability manifests as an insecure deserialization flaw within the Go Live Update Urls plugin (<= 7.0.8).\nRoot Cause: The plugin incorrectly handles user-supplied data that is passed directly to the PHP unserialize() function without sufficient sanitization or validation. In PHP, the unserialize() function converts a stored string representation back into a PHP value or object.\nWhen an attacker provides a crafted serialized string, the PHP engine instantiates objects based on the provided data. If the application environment contains 'gadget chains'—classes that implement magic methods such as __wakeup(), __destruct(), or __toString()—the attacker can leverage these methods to execute arbitrary code or interact with system files during the object's lifecycle.\nAttack Flow: 1. The attacker identifies a plugin endpoint or parameter that accepts serialized data intended for internal processing. 2. The attacker crafts a malicious payload using a PHP gadget chain that targets a vulnerable class present in the WordPress core, theme, or other installed plugins. 3. This payload is transmitted via a GET or POST request to the target system. 4. The vulnerable function within the Go Live Update Urls plugin calls unserialize() on the malicious input. 5. The PHP engine processes the input, instantiating the attacker's object and invoking the associated magic methods. 6. The gadget chain executes, allowing the attacker to perform unauthorized operations, such as escalating privileges, reading sensitive configuration files, or executing system commands.\nExploitation Requirements: The success of this exploit is dependent on the application's configuration and the presence of accessible classes that can be used to construct a functional gadget chain. While the plugin facilitates the entry point, the actual impact is often contingent on the wider WordPress ecosystem (e.g., loaded libraries).\nAffected Components: The primary vulnerable component involves the handling of update URL configurations and data retrieval routines within the plugin's internal logic. All versions up to and including 7.0.8 are impacted.\nPost-Exploitation: Once the deserialization is successfully triggered, the attacker's ability is bounded only by the permissions of the web server user (typically www-data or similar). This may lead to the installation of web shells, modification of database records, or lateral movement within the hosting infrastructure."
}