CVE-2024-8030Disclosure(bdthemes / ultimate_store_kit)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_wishlist cookie in versions up to , and including, 2.0.3. This makes it possible for an unauthenticated attacker to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker or above to delete arbitrary files, retrieve sensitive data, or execute code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ultimate_store_kit

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ultimate_store_kit

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-08: 1Technical Details · 2026-04-08: 104-08
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2024-8030: Ultimate Store Kit Elementor Addo... Cookie-based PHP object injection in WordPress e-commerce plugin hits CVSS 9.8 - unauthenticated RCE waiting for the rig... https://zerodaysignal.com/vulnerability/CVE-2024-8030 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses CVE-2024-8030, a cookie-based PHP object injection vulnerability in the Ultimate Store Kit Elementor Addon plugin that allows unauthenticated remote code execution with a CVSS score of 9.8.

    0000081
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbdthemesultimate_store_kit-wordpress-

Explore more