WordPress Plugin Vulnerabilities

Lucky Wheel for WooCommerce – Spin a Sale < 1.1.14 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags

Description

The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13. This is due to the plugin using eval() to execute user-supplied input from the 'Conditional Tags' setting without proper validation or sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server. In WordPress multisite installations, this allows Site Administrators to execute arbitrary code, a capability they should not have since plugin/theme file editing is disabled for non-Super Admins in multisite environments.

Affects Plugins

Fixed in 1.1.14

References

Classification

Type
RCE
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Nguyen Truong (Roll)
Verified
No

Timeline

Publicly Published
2025-12-29 (about 7 months ago)
Added
2025-12-29 (about 7 months ago)
Last Updated
2025-12-30 (about 7 months ago)

Other