What the vulnerability does
01Description
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
Explanation of Vulnerability in Simple Terms
The Novalnet Payment Gateway for WooCommerce versions up to 12.10.3 contain a deserialization vulnerability that allows unauthenticated attackers to run arbitrary code on the site. The vulnerability exists in how the plugin processes untrusted serialized data without proper validation. No user interaction is required to exploit this issue.
What an attacker can do
Run arbitrary code on your site and take complete control of it.
Potential impact on your site
Complete site compromise: attackers can steal data, modify content, install malware, or shut down your store.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities