PT-2024-39323 · Woocommerce · Product Enquiry For Woocommerce

Francesco Carlucci

·

Published

2024-09-26

·

Updated

2024-10-04

·

CVE-2024-8922

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: The Product Enquiry for WooCommerce versions up to, and including, 2.2.33.32
Description: The vulnerability concerns PHP Object Injection via deserialization of untrusted input in enquiry detail.php. This allows authenticated attackers with Author-level access and above to inject a PHP Object. No known POP chain is present in the vulnerable software, but if a POP chain is present via an additional plugin or theme, it could enable the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations: For versions up to, and including, 2.2.33.32, update to a version that fixes the PHP Object Injection issue. As a temporary workaround, consider restricting access to the enquiry detail.php file until a patch is available. Avoid using untrusted input in the enquiry detail.php file to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-8922

Affected Products

Product Enquiry For Woocommerce