The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
https://wpscan.com/vulnerability/c7eb234e-3113-40db-a00d-358604d91e3f/