Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affects WC Price History for Omnibus: from n/a through <= 2.1.4.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-22510, a PHP Object Injection vulnerability in the WordPress plugin 'WC Price History for Omnibus' (versions <= 2.1.4). The exploit leverages the plugin's 'Import debug data' feature, accessible via the WooCommerce dashboard at '/wp-admin/admin.php?page=wc-price-history', which allows Shop Manager (or higher) users to upload a JSON file. The JSON file contains a 'serialized' key with a PHP serialized object. The plugin's import handler deserializes this data without validation, leading to PHP Object Injection. The provided PoC demonstrates how an attacker can trigger the __destruct() method of a custom class by uploading a crafted JSON file. The repository contains a sample PoC.json file with the serialized payload and a detailed README.md explaining the vulnerability, exploitation steps, and references. No actual exploit code is present beyond the serialized payload; the exploit's success depends on the presence of a suitable POP chain in the target environment.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.