CVE · High

CVE-2017-18356 — WooCommerce [woocommerce] < 3.2.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-18356 WooCommerce [woocommerce] < 3.2.4 Improper Control of Generation of Code ('Code Injection') High 8.8 < 3.2.4 3.2.4 2017-11-16

CVE-2017-18356

The WooCommerce plugin before version 3.2.4 contains a PHP object injection vulnerability in its product shortcode functionality that can be exploited by attackers with Shop manager-level or higher privileges. By submitting a maliciously crafted input string, an attacker can inject arbitrary PHP objects through the query caching mechanism in the WC_Shortcode_Products class. This vulnerability requires authenticated access to the WordPress site but allows an authenticated attacker with sufficient permissions to execute arbitrary code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.