Sceawere

Vulnerability Detail

CVE-2026-96343UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP ERP PHP Object Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
weDevs
Product
WP ERP
Attack Type
CWE-502 Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-30T13:17:29.167Z",
  "pubdate": "2026-09-30T13:17:29.167Z",
  "executiveSummary": "The WP ERP plugin for WordPress, in versions 1.17.9 and earlier, contains a PHP Object Injection vulnerability.\nThis vulnerability stems from insecure deserialization of user-supplied data within the custom role management functionality.\nAn unauthenticated or authenticated attacker can leverage this flaw to inject malicious serialized objects into the application, potentially leading to remote code execution (RCE), unauthorized file deletion, or sensitive data access.\nSuccessful exploitation requires the presence of 'POP chains' (Property Oriented Programming) within the application's codebase or bundled libraries that allow the attacker to manipulate object properties and trigger unintended execution paths during the wakeup or destruction phases.\nThe risk is critical due to the potential for complete system compromise if an attacker identifies a viable gadget chain within the environment.\nUsers are strongly advised to update to a patched version immediately to mitigate the risk of exploitation.",
  "technicalDetails": "The vulnerability is rooted in the insecure use of the unserialize() PHP function on input that is susceptible to user tampering. Within the custom role management modules of WP ERP, serialized data is processed without adequate validation or sanitization, allowing an attacker to supply a crafted serialized string.\nPHP Object Injection occurs when an application deserializes untrusted data into an object, and the magic methods (such as __wakeup(), __destruct(), or __toString()) are subsequently triggered. By controlling the property values of the injected object, an attacker can manipulate the internal state of the application's runtime environment.\nThe attack flow begins when an attacker crafts a malicious payload containing a serialized object. This payload is delivered to the vulnerable endpoint responsible for handling custom role data. Once the server calls unserialize() on this input, the PHP engine instantiates the object based on the provided class definition. If the class definition contains magic methods that interact with object properties in a way that executes arbitrary code or performs filesystem operations—referred to as a POP chain—the attacker can achieve code execution within the context of the web server process.\nThis issue affects all versions of WP ERP up to and including 1.17.9. The vulnerability is typically accessible over the network, and the requirements for exploitation depend on the availability of classes with exploitable magic methods within the WordPress core, the WP ERP plugin, or other installed plugins and themes.\nUpon successful exploitation, the impact is severe. Depending on the available gadget chains, an attacker may be able to execute arbitrary PHP code, allowing them to install backdoors, escalate privileges, steal database credentials, or exfiltrate sensitive site data. Because the exploit occurs at the application layer, traditional network-based firewalls may not detect the malicious payload unless they are specifically configured to inspect and sanitize serialized data streams.\nThe vulnerability demonstrates a failure to implement secure coding practices for data handling. Developers should avoid deserializing complex objects from untrusted sources and prefer secure data formats like JSON, which do not inherently trigger object instantiation or magic method execution."
}
CVE-2026-96343: WP ERP PHP Object Injection (HIGH Severity, CVSS: 7.2) | Sceawere