SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-84099

HIGH · CVSS 8.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The wpstorecart WordPress plugin versions up to 5.0.7 are vulnerable to unauthenticated access, allowing attackers to exploit a deserialization flaw in a bundled add-on. This vulnerability enables the injection of arbitrary PHP objects, potentially leading to remote code execution if a suitable gadget chain exists on the site. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-84099
Severity
HIGH
CVSS
8.1
EPSS
0.27%
WordPress

Original NVD Description

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.