Unrated severityNVD Advisory· Published Sep 12, 2026
CVE-2026-84099
CVE-2026-84099
Description
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=5.0.7+ 1 more
- (no CPE)range: <=5.0.7
- (no CPE)range: <=5.0.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.