What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from n/a through 6.1.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
What the vulnerability does
Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from n/a through 6.1.3.
Explanation of Vulnerability in Simple Terms
WooCommerce Product Add-Ons versions up to 6.1.3 contain a deserialization vulnerability that allows high-privilege users to execute arbitrary code on the site. An attacker with admin or shop manager access can craft malicious serialized data that, when processed by the plugin, runs their own PHP code. This affects the integrity and availability of the site.
What an attacker can do
Run arbitrary PHP code on the site with admin-level privileges.
Potential impact on your site
A compromised admin account can be used to inject malicious code, modify site data, or take full control of the site.
Conditions required to exploit
Attacker must have high-level access (admin or shop manager role) to the WordPress site.
Key dates
External resources
Related vulnerabilities