SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments <= 4.9.3 - Authenticated (Shop Worker+) PHP Object Injection via Integrations REST API

Medium 6.6 CWE-502Fixed in 4.9.4
ID
WPSEC-2026-0709
Plugin
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments (surecart)
Affected
all versions before 4.9.4
Remediation
Update to 4.9.4 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-502
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments on WPSec AttackSurface
Fix released
Published

Description

The SureCart plugin for WordPress is vulnerable to PHP Object Injection via the integrations REST API endpoint (/surecart/v1/integrations) in all versions up to, and including, 4.9.3, due to deserialization of untrusted input when local database models fill their attributes. Every attribute value was passed through maybe_unserialize() twice without restricting allowed classes, and request parameters such as 'integration_id', 'price_id' and 'variant_id' are passed to the model unchanged. This makes it possible for authenticated attackers with SureCart Shop Worker-level access and above to inject a PHP object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via another plugin or theme installed on the target system, it may allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0