๐Ÿ” CVE Alert

CVE-2026-84099

HIGH 8.1

IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.

Vendor unknown
Product wpstorecart
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpstorecart

Be the first to know when new high vulnerabilities affecting unknown wpstorecart are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / wpstorecart
0 โ‰ค 5.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/11d36ab2-ac8d-42cf-91c0-dea55d7edc9a/

Credits

reconnaissance WPScan