The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
History

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Ecommerce
Wp Ecommerce wp Ecommerce
Vendors & Products Wordpress
Wordpress wordpress
Wp Ecommerce
Wp Ecommerce wp Ecommerce

Wed, 11 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Title WP eCommerce <= 3.15.1 - Unauthenticated PHP Object Injection
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-02-11T15:54:37.663Z

Reserved: 2026-01-20T16:01:12.343Z

Link: CVE-2026-1235

cve-icon Vulnrichment

Updated: 2026-02-11T15:52:49.513Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-11T06:15:51.220

Modified: 2026-02-11T16:16:03.583

Link: CVE-2026-1235

cve-icon Redhat

No data.