The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.
- https://wpvulndb.com/vulnerabilities/9292
- https://github.com/20142995/nuclei-templates