Sceawere
Vulnerability Detail
CVE-2026-96344UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
eCommerce Product Catalog PHP Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- impleCode
- Product
- eCommerce Product Catalog
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-09-30T13:17:29.300Z",
"pubdate": "2026-09-30T13:17:29.300Z",
"executiveSummary": "The eCommerce Product Catalog plugin for WordPress, in versions 3.6.0 and below, is susceptible to a PHP Object Injection vulnerability. This security flaw originates from improper handling of user-supplied data that is passed into PHP's unserialize() function.\nA remote, authenticated attacker with sufficient privileges can exploit this vulnerability by injecting a crafted serialized object into the application. Upon deserialization, the application may inadvertently trigger unintended code paths, leading to arbitrary code execution, unauthorized data modification, or denial-of-service conditions.\nThe vulnerability poses a severe risk to the integrity, availability, and confidentiality of the affected WordPress site. Successful exploitation grants an attacker the ability to execute arbitrary PHP code within the context of the web server. This vulnerability does not require complex infrastructure and can be exploited over the network. It is recommended to restrict access to administrative functions and ensure the plugin is updated to a patched version once available.",
"technicalDetails": "The root cause of this vulnerability lies in the unsafe deserialization of untrusted input within the eCommerce Product Catalog plugin. PHP Object Injection occurs when an application calls the unserialize() function on data provided by the user without performing adequate validation or sanitization.\nIn the context of the eCommerce Product Catalog, the application likely accepts serialized data through a specific request parameter or a POST variable, which is then processed by a vulnerable component or function. Because PHP's unserialize() function automatically instantiates objects and calls magic methods such as __wakeup() or __destruct() based on the provided serialized string, an attacker can manipulate this process to achieve unintended behaviors.\nThe attack flow begins with the attacker identifying the specific input vector that handles serialized data. The attacker crafts a malicious serialized payload containing a gadget chain—a sequence of existing code components within the application's environment or the plugin itself. These gadget chains are designed to manipulate the application state, leak sensitive information, or execute arbitrary commands upon the destruction or wake-up of the injected objects.\nExploitation requires the attacker to be authenticated with privileges that allow access to the vulnerable functionality, often associated with administrative or plugin-specific settings. Once the payload is submitted via HTTP request, the vulnerable function processes the unserialized input. The PHP interpreter reconstructs the object, triggering the gadget chain within the application scope.\nThe post-exploitation impact is critical, as it allows for Remote Code Execution (RCE). An attacker can leverage this access to perform file system operations, interact with the WordPress database, or escalate privileges within the WordPress environment. Given the nature of PHP Object Injection, the exact impact is constrained by the classes available in the scope of the web application at the time of deserialization. However, typical payloads aim to override properties of objects that are subsequently used in sensitive operations, such as database queries or file inclusions, facilitating complete site takeover."
}