CVE-2017-18356
The WooCommerce plugin before version 3.2.4 contains a PHP object injection vulnerability in its product shortcode functionality that can be exploited by attackers with Shop manager-level or higher privileges. By submitting a maliciously crafted input string, an attacker can inject arbitrary PHP objects through the query caching mechanism in the WC_Shortcode_Products class. This vulnerability requires authenticated access to the WordPress site but allows an authenticated attacker with sufficient permissions to execute arbitrary code.
Based on public CVE data (MITRE/NVD).