Custom Product Tabs For WooCommerce <= 1.2.4 - Authenticated (Shop Manager+) PHP Object Injection
highThe Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.4 via deserialization of untrusted input from the 'wb_custom_tabs' parameter. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inje...
- CVSS:
- 7.2
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.5
- Disclosed:
- Dec 20, 2024