Sceawere

Vulnerability Detail

CVE-2026-96832UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Content Egg PHP Object Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
keywordrush
Product
Content Egg
Attack Type
CWE-502 Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-30T13:17:33.023Z",
  "pubdate": "2026-09-30T13:17:33.023Z",
  "executiveSummary": "Content Egg versions 6.3.1 and below contain a critical PHP Object Injection vulnerability within the Shop manager component.\nThis vulnerability arises from the insecure deserialization of user-supplied input, which can be leveraged by an authenticated attacker to manipulate serialized objects.\nSuccessful exploitation allows for arbitrary PHP object injection, potentially leading to Remote Code Execution (RCE), arbitrary file deletion, or sensitive data exposure depending on the available gadget chains within the application's environment.\nThe vulnerability poses a severe risk to the integrity and availability of the WordPress installation, as it enables attackers to bypass intended security controls and execute arbitrary code in the context of the web server process.\nExploitation requires an attacker to possess Shop manager-level privileges or higher to access the vulnerable functionality. No specialized network access beyond standard web connectivity is required once authenticated.",
  "technicalDetails": "The vulnerability exists within the Content Egg plugin due to the improper handling of serialized data passed to the application. The Shop manager functionality processes user-supplied input that is subsequently passed into a PHP deserialization function, such as unserialize(), without adequate validation or sanitization.\nIn PHP, the unserialize() function can be dangerous if the input is untrusted, as it can instantiate objects of any class currently defined in the application's scope. By crafting a malicious serialized string, an attacker can manipulate the properties of these objects, which may trigger unintended behavior during object destruction or method invocation if specific 'magic methods' (such as __destruct(), __wakeup(), or __toString()) are present within the codebase.\nThe attack flow begins with the attacker identifying the specific input vector within the Shop manager interface that accepts serialized data. The attacker then constructs a payload containing a serialized object chain. When this payload is processed by the application, the underlying PHP engine reconstructs the object. If a suitable 'gadget chain' exists—a sequence of existing class methods that perform sensitive operations—the attacker can achieve unintended side effects.\nBy manipulating these objects, the attacker may gain the ability to execute arbitrary commands on the host server if the chain facilitates file system manipulation, memory corruption, or dynamic code evaluation. This vulnerability is compounded by the fact that many WordPress environments include numerous third-party plugins and themes, which significantly increases the number of available gadget chains that can be chained together to achieve full Remote Code Execution (RCE).\nThis flaw affects Content Egg versions 6.3.1 and lower. The vulnerability is triggered during the processing of requests where the plugin's Shop manager logic attempts to deserialize configuration or session data derived from user input. Post-exploitation, an attacker could maintain persistence, exfiltrate database credentials, or gain full administrative control over the compromised WordPress site."
}
CVE-2026-96832: Content Egg PHP Object Injection (HIGH Severity, CVSS: 7.2) | Sceawere