SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments <= 4.9.3 - Authenticated (Shop Worker+) PHP Object Injection via Integrations REST API
- ID
- WPSEC-2026-0709
- Plugin
- SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments (surecart)
- Affected
- all versions before 4.9.4
- Remediation
- Update to 4.9.4 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-502
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments on WPSec AttackSurface
- Fix released
- Published
Description
The SureCart plugin for WordPress is vulnerable to PHP Object Injection via the integrations REST API endpoint (/surecart/v1/integrations) in all versions up to, and including, 4.9.3, due to deserialization of untrusted input when local database models fill their attributes. Every attribute value was passed through maybe_unserialize() twice without restricting allowed classes, and request parameters such as 'integration_id', 'price_id' and 'variant_id' are passed to the model unchanged. This makes it possible for authenticated attackers with SureCart Shop Worker-level access and above to inject a PHP object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via another plugin or theme installed on the target system, it may allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
References
- https://wpsec.com/vuln/WPSEC-2026-0709/
- https://plugins.svn.wordpress.org/surecart/tags/4.9.4/
- https://wordpress.org/plugins/surecart/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS