Description

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_wishlist cookie in versions up to , and including, 2.0.3. This makes it possible for an unauthenticated attacker to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker or above to delete arbitrary files, retrieve sensitive data, or execute code.

INFO

Published Date :

2024-08-28T02:05:47.143Z

Last Modified :

2026-04-08T17:31:56.985Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8030 vulnerability.

Vendors Products
Bdthemes
  • Ultimate Store Kit
  • Utlimate Store Kit Elementor Addons

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact