Object Injection Vulnerability in WP Hosting AS Pay with Vipps Plugin for WooCommerce
CVE-2026-94568
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 October 2026
What is CVE-2026-94568?
The Pay with Vipps for WooCommerce plugin contains a vulnerability where untrusted data can be deserialized, allowing potential object injection. This flaw could be exploited by attackers to manipulate the application and possibly gain unauthorized access to sensitive information or execute arbitrary code. The affected versions range from n/a to 6.2.0.
Affected Version(s)
Pay with Vipps for WooCommerce 0 <= 6.2.0