WordPress YITH WooCommerce Product Add-Ons Plugin <= 4.3.0 is vulnerable to PHP Object Injection
CVE-2023-49777
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 December 2023
What is CVE-2023-49777?
A vulnerability has been identified in the YITH WooCommerce Product Add-Ons plugin that allows for deserialization of untrusted data. This weakness can be exploited through external scripts leading to PHP object injection, potentially allowing unauthorized access and manipulation of user data. The affected versions are from not available through 4.3.0, making it crucial for users to update and secure their installations.
Affected Version(s)
YITH WooCommerce Product Add-Ons <= 4.3.0