Deserialization Vulnerability in mklacroix Product Configurator for WooCommerce
CVE-2026-105872
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 October 2026
What is CVE-2026-105872?
A vulnerability in the mklacroix Product Configurator for WooCommerce allows attackers to exploit deserialization of untrusted data, leading to potential object injection. This issue impacts all versions from an unspecified release up to version 1.7.5, posing risks to web application integrity when utilizing this plugin.
Affected Version(s)
Product Configurator for WooCommerce 0 <= 1.7.5