WooCommerce Recover Abandoned Cart PHP Object Injection Vulnerability
Vulnerability
A PHP Object Injection vulnerability has been identified in the WooCommerce Recover Abandoned Cart plugin for WordPress, affecting all versions through 24.4.0. The vulnerability arises from the deserialization of untrusted data from the 'raccookie_guest_email' cookie, allowing unauthenticated attackers to inject PHP objects. While the vulnerable plugin itself does not have a known payload execution chain, the vulnerability could be exploited if another plugin or theme with a compatible chain is installed, potentially leading to unauthorized file deletion, sensitive data exposure, or arbitrary code execution.
Impact
Exploitation of this vulnerability could allow for PHP Object Injection, with the possibility of executing actions such as deleting files, accessing sensitive information, or executing code, but only if an additional plugin or theme that facilitates such exploitation is present on the site.
Remediation
Users are advised to update the WooCommerce Recover Abandoned Cart plugin to version 24.5.0 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
