PHP Object Injection Vulnerability in Custom Product Tabs Lite for WooCommerce by WordPress
CVE-2024-12600
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 January 2025
What is CVE-2024-12600?
The Custom Product Tabs Lite for WooCommerce plugin allows an authenticated user with Shop Manager-level access and above to exploit a vulnerability through the deserialization of untrusted input in the 'frs_woo_product_tabs' parameter. This can lead to the injection of a PHP Object. Although the current software lacks a known Proof of Concept (POP) chain, if other plugins or themes on the system introduce a POP chain, it may enable attackers to delete files, access sensitive information, or execute arbitrary code.
Affected Version(s)
Custom Product Tabs Lite for WooCommerce * <= 1.9.0