CVE 6.5 MEDIUM

WP eCommerce <= 3.15.1 - Unauthenticated PHP Object Injection_CVE-2026-1235

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

Description

The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

Basic Information

ID CVE-2026-1235
Source WPScan
Published Feb 11, 2026 at 06:00
Modified Feb 11, 2026 at 15:54

Affected Product

Vendor Unknown
Product WP eCommerce
Affected Versions Unknown WP eCommerce 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.