CVE-2026-84099 PUBLISHED

IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php

Assigner: WPScan
Reserved: 01.09.2026 Published: 12.09.2026 Updated: 12.09.2026

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.

Product Status

Vendor Unknown
Product wpstorecart
Versions Default: unknown
  • affected from 0 to 5.0.7 (incl.)

Credits

  • reconnaissance finder
  • WPScan coordinator

References

Problem Types

  • CWE-502 Deserialization of Untrusted Data CWE