The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 11 Feb 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. | |
| Title | WP eCommerce <= 3.15.1 - Unauthenticated PHP Object Injection | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-02-11T06:00:08.398Z
Reserved: 2026-01-20T16:01:12.343Z
Link: CVE-2026-1235
No data.
Status : Received
Published: 2026-02-11T06:15:51.220
Modified: 2026-02-11T06:15:51.220
Link: CVE-2026-1235
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.