# SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments <= 4.9.3 - Authenticated (Shop Worker+) PHP Object Injection via Integrations REST API

- **ID:** WPSEC-2026-0709
- **Plugin:** SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments (`surecart`), https://wordpress.org/plugins/surecart/
- **Affected versions:** all versions before 4.9.4
- **Fixed in:** 4.9.4 (Update to 4.9.4 or later.)
- **Severity:** Medium 6.6 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-502
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/surecart
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0709/

## Description

The SureCart plugin for WordPress is vulnerable to PHP Object Injection via the integrations REST API endpoint (/surecart/v1/integrations) in all versions up to, and including, 4.9.3, due to deserialization of untrusted input when local database models fill their attributes. Every attribute value was passed through maybe_unserialize() twice without restricting allowed classes, and request parameters such as 'integration_id', 'price_id' and 'variant_id' are passed to the model unchanged. This makes it possible for authenticated attackers with SureCart Shop Worker-level access and above to inject a PHP object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via another plugin or theme installed on the target system, it may allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

## References

- https://wpsec.com/vuln/WPSEC-2026-0709/
- https://plugins.svn.wordpress.org/surecart/tags/4.9.4/
- https://wordpress.org/plugins/surecart/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0709/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
