Sceawere
Vulnerability Detail
CVE-2026-96343UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP ERP PHP Object Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- weDevs
- Product
- WP ERP
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-09-30T13:17:29.167Z",
"pubdate": "2026-09-30T13:17:29.167Z",
"executiveSummary": "The WP ERP plugin for WordPress, in versions 1.17.9 and earlier, contains a PHP Object Injection vulnerability.\nThis vulnerability stems from insecure deserialization of user-supplied data within the custom role management functionality.\nAn unauthenticated or authenticated attacker can leverage this flaw to inject malicious serialized objects into the application, potentially leading to remote code execution (RCE), unauthorized file deletion, or sensitive data access.\nSuccessful exploitation requires the presence of 'POP chains' (Property Oriented Programming) within the application's codebase or bundled libraries that allow the attacker to manipulate object properties and trigger unintended execution paths during the wakeup or destruction phases.\nThe risk is critical due to the potential for complete system compromise if an attacker identifies a viable gadget chain within the environment.\nUsers are strongly advised to update to a patched version immediately to mitigate the risk of exploitation.",
"technicalDetails": "The vulnerability is rooted in the insecure use of the unserialize() PHP function on input that is susceptible to user tampering. Within the custom role management modules of WP ERP, serialized data is processed without adequate validation or sanitization, allowing an attacker to supply a crafted serialized string.\nPHP Object Injection occurs when an application deserializes untrusted data into an object, and the magic methods (such as __wakeup(), __destruct(), or __toString()) are subsequently triggered. By controlling the property values of the injected object, an attacker can manipulate the internal state of the application's runtime environment.\nThe attack flow begins when an attacker crafts a malicious payload containing a serialized object. This payload is delivered to the vulnerable endpoint responsible for handling custom role data. Once the server calls unserialize() on this input, the PHP engine instantiates the object based on the provided class definition. If the class definition contains magic methods that interact with object properties in a way that executes arbitrary code or performs filesystem operations—referred to as a POP chain—the attacker can achieve code execution within the context of the web server process.\nThis issue affects all versions of WP ERP up to and including 1.17.9. The vulnerability is typically accessible over the network, and the requirements for exploitation depend on the availability of classes with exploitable magic methods within the WordPress core, the WP ERP plugin, or other installed plugins and themes.\nUpon successful exploitation, the impact is severe. Depending on the available gadget chains, an attacker may be able to execute arbitrary PHP code, allowing them to install backdoors, escalate privileges, steal database credentials, or exfiltrate sensitive site data. Because the exploit occurs at the application layer, traditional network-based firewalls may not detect the malicious payload unless they are specifically configured to inspect and sanitize serialized data streams.\nThe vulnerability demonstrates a failure to implement secure coding practices for data handling. Developers should avoid deserializing complex objects from untrusted sources and prefer secure data formats like JSON, which do not inherently trigger object instantiation or magic method execution."
}