MarketPress <= 3.2.6 - Unauthenticated PHP Object Injection

2017-10-01 00:00
Anonymous

Strategic Overview

Status
Patched in 3.2.7
Affected Version<= 3.2.6
CVSS9.8Critical
CVEN/A
View all MarketPress – WordPress eCommerce vulnerabilities

Vulnerability Overview

The MarketPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.2.6 via deserialization of untrusted input mp_globalcart_* cookie value. This allows unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary PHP code in the scope of the vulnerable service.

Technical Analysis

REMEDIATION: Update to version 3.2.7, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C