CVE-2024-8030: Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.0.3 - Unauthenticated PHP Object Injection
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the ultimatestorekitwishlist cookie in versions up to , and including, 2.0.3. This makes it possible for an unauthenticated attacker to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker or above to delete arbitrary files, retrieve sensitive data, or execute code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8030?
CVE-2024-8030 has a high severity due to its potential for PHP Object Injection, which can lead to unauthorized access or control over the server.
How do I fix CVE-2024-8030?
To fix CVE-2024-8030, update the Ultimate Store Kit Elementor Addons plugin to version 2.0.4 or later, which eliminates the vulnerability.
What versions are affected by CVE-2024-8030?
CVE-2024-8030 affects versions of the Ultimate Store Kit Elementor Addons plugin up to and including version 2.0.3.
What kind of attack is CVE-2024-8030 associated with?
CVE-2024-8030 is associated with PHP Object Injection attacks that exploit deserialization of untrusted input.
Is CVE-2024-8030 specific to certain plugins?
Yes, CVE-2024-8030 specifically affects the Ultimate Store Kit Elementor Addons plugin used for WooCommerce and EDD.