Description
Unauthenticated PHP Object Injection in Payever - WooCommerce Gateway <= 4.8.2 versions.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Unauthenticated PHP Object Injection vulnerability is present in Payever – WooCommerce Gateway plugin versions up to 4.8.2. The flaw allows an attacker to instantiate arbitrary PHP objects without authentication and execute arbitrary code within the WordPress environment. This can compromise the confidentiality, integrity, and availability of the host system, as illustrated by CWE‑502. The likely attack vector is sending a crafted serialized payload to the plugin’s entry point, though the exact endpoint is not specified and is inferred from typical object injection patterns.

Affected Systems

The affected product is Payever – WooCommerce Gateway for WordPress. All installations running version 4.8.2 or earlier are vulnerable; newer releases are not affected.

Risk and Exploitability

The CVSS score of 9.8 reflects the high severity of this vulnerability. Although EPSS is not available and the issue is not listed in CISA KEV catalog, the lack of authentication requirement and the likely high potential for automated exploitation in the WordPress ecosystem suggest a significant risk. Based on the description, the likely attack vector is delivering a crafted request to the plugin’s entry point, creating malicious objects that lead to remote code execution.

Generated by OpenCVE AI on October 10, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Payever – WooCommerce Gateway plugin version (>=4.8.3).
  • If upgrading is not immediately possible, temporarily deactivate or uninstall the plugin to eliminate the attack surface.
  • Configure the web server and PHP settings to restrict object serialization and enforce strict permissions on the plugin’s directory.

Generated by OpenCVE AI on October 10, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in Payever - WooCommerce Gateway <= 4.8.2 versions.
Title WordPress Payever - WooCommerce Gateway plugin <= 4.8.2 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:16.768Z

Reserved: 2026-04-29T09:05:14.679Z

Link: CVE-2026-42716

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:36.630

Modified: 2026-10-10T20:16:36.630

Link: CVE-2026-42716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T22:30:17Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data