PT-2024-38758 · Unknown · Edd Builder+6
Francesco Carlucci
·
Published
2024-08-27
·
Updated
2026-04-08
·
CVE-2024-8030
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin versions up to, and including, 2.0.3
Description:
The issue is related to PHP Object Injection via deserialization of untrusted input via the
ultimate store kit wishlist cookie. This allows an unauthenticated attacker to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.Recommendations:
For versions up to, and including, 2.0.3, upgrade to a newer version to patch the vulnerability. As a temporary workaround, consider restricting access to the
ultimate store kit wishlist cookie to minimize the risk of exploitation. Additionally, ensure that no POP chain is present in any installed plugins or themes to prevent further exploitation.Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edd Builder
Elementor Store Builder
Product Grid
Product Table
Bdthemes Ultimate Store Kit Elementor Addons
Woocommerce Builder
Woocommerce Slider Plugin