Description
WordPress Plugin WooCommerce is prone to a vulnerability that lets remote attackers inject arbitrary code because the application fails to sanitize user-supplied input before being passed to the maybe_unserialize() function. Attackers can possibly exploit this issue to download any file on the vulnerable server. WordPress Plugin WooCommerce version 2.3.10 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.11 or latest
References
https://blog.sucuri.net/2015/06/security-advisory-object-injection-vulnerability-in-woocommerce.html
Related Vulnerabilities
Jetty Uncontrolled Resource Consumption Vulnerability (CVE-2025-5115)
WordPress Plugin iThemes Security (formerly Better WP Security) Security Bypass (7.9.0)
WordPress Plugin WooCommerce Weight Based Shipping Cross-Site Request Forgery (5.4.1)
Apache Traffic Server Incorrect Behavior Order Vulnerability (CVE-2026-65100)