CVE-2024-5335General(bdthemes / ultimate_store_kit)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_compare_products cookie in versions up to , and including, 1.6.4. This makes it possible for an unauthenticated attacker to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker or above to delete arbitrary files, retrieve sensitive data, or execute code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ultimate_store_kit

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ultimate_store_kit

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-08: 1Technical Details · 2026-04-08: 104-08
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    General

    🚨 CVE-2024-5335: Ultimate Store Kit Elementor Addo... Cookie-based PHP object injection with CVSS 9.8 - one malicious request away from RCE if target runs vulnerable themes/p... https://zerodaysignal.com/vulnerability/CVE-2024-5335 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post alerts about CVE‑2024‑5335, noting a cookie‑based PHP object injection and a high CVSS score with RCE potential, but does not provide a PoC, exploit code, or patch information.

    0000047
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbdthemesultimate_store_kit-wordpress-

Explore more