Impact
Unauthenticated PHP Object Injection (CWE‑502) exists in the Novalnet Payment Gateway for WooCommerce plugin for WordPress versions 12.10.3 and earlier. The flaw allows an attacker to send specially crafted input that instructs the plugin to instantiate arbitrary PHP objects. This injection can lead to execution of arbitrary code on the server, compromising confidentiality, integrity, and availability of the site and potentially the underlying host system.
Affected Systems
WordPress sites that have the Novalnet Payment Gateway for WooCommerce plugin installed at version 12.10.3 or earlier are impacted. The affected product is the Novalnet Payment Gateway for WooCommerce, a payment gateway integration plugin for WooCommerce. Only sites running the listed versions of this plugin should assess whether it is deployed and determine the need for remediation.
Risk and Exploitability
The CVSS score of 9.8 classifies the vulnerability as critical, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The issue is not listed in CISA KEV. Attackers can exploit the flaw remotely and without authentication by sending crafted requests to the plugin’s endpoints, so any visitor to a vulnerable site could attempt exploitation. The combination of unauthenticated remote access, high severity, and low exploitation likelihood makes it a high‑priority risk for sites that have not applied the available patch.
OpenCVE Enrichment