CVE-2024-4606 MEDIUM

CVE-2024-4606: WordPress Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder plugin <= 2.0.3 - PHP Object Injection vulnerability

Vendor Bdthemes
Product Ultimate Store Kit Elementor Addons
Weakness CWE-502 · Unsafe deserialization
Published May 9, 2024
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in BdThemes Ultimate Store Kit Elementor Addons.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.0.3.

Explanation of Vulnerability in Simple Terms

02Summary

Ultimate Store Kit Elementor Addons versions up to 2.0.3 contain a deserialization vulnerability that allows an attacker to send malicious serialized data to the plugin. When the plugin processes this data without proper validation, an attacker can read sensitive information or modify site data. The attack requires specific conditions to succeed but does not require authentication.

What an attacker can do

03Attacker Capabilities

Read sensitive site data or modify content by sending malicious serialized data to the plugin.

Potential impact on your site

04Site Impact

Attackers could access private information or alter site content without needing a user account.

Conditions required to exploit

05Prerequisites

Network access to the site; specific conditions must be met for exploitation to succeed.

Key dates

06Disclosure timeline

May 9, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE