PT-2025-1811 · WordPress · Compare Products For Woocommerce

Brian Sans-Souci

+1

·

Published

2025-01-07

·

Updated

2025-01-12

·

CVE-2024-12313

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Compare Products for WooCommerce plugin for WordPress versions up to, and including, 3.2.1
Description The issue concerns a PHP Object Injection vulnerability in the Compare Products for WooCommerce plugin for WordPress. This vulnerability occurs through the deserialization of untrusted input from the woo compare list cookie, allowing unauthenticated attackers to inject a PHP object. No known POP chain is present in the vulnerable software. However, if a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations For versions up to, and including, 3.2.1, update to a version higher than 3.2.1 to resolve the issue. As a temporary workaround, consider restricting access to the woo compare list cookie to minimize the risk of exploitation. Additionally, review installed plugins and themes for potential POP chains that could exacerbate the vulnerability.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-12313

Affected Products

Compare Products For Woocommerce