CyberRota Analysis
AI-GeneratedThe wpstorecart WordPress plugin versions up to 5.0.7 are vulnerable to unauthenticated access, allowing attackers to exploit a deserialization flaw in a bundled add-on. This vulnerability enables the injection of arbitrary PHP objects, potentially leading to remote code execution if a suitable gadget chain exists on the site. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.