What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in BdThemes Ultimate Store Kit Elementor Addons.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.0.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Deserialization of Untrusted Data vulnerability in BdThemes Ultimate Store Kit Elementor Addons.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.0.3.
Explanation of Vulnerability in Simple Terms
Ultimate Store Kit Elementor Addons versions up to 2.0.3 contain a deserialization vulnerability that allows an attacker to send malicious serialized data to the plugin. When the plugin processes this data without proper validation, an attacker can read sensitive information or modify site data. The attack requires specific conditions to succeed but does not require authentication.
What an attacker can do
Read sensitive site data or modify content by sending malicious serialized data to the plugin.
Potential impact on your site
Attackers could access private information or alter site content without needing a user account.
Conditions required to exploit
Network access to the site; specific conditions must be met for exploitation to succeed.
Key dates
External resources
Related vulnerabilities