Description
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
Published: 2026-07-02
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated PHP Object Injection (CWE‑502) exists in the Novalnet Payment Gateway for WooCommerce plugin for WordPress versions 12.10.3 and earlier. The flaw allows an attacker to send specially crafted input that instructs the plugin to instantiate arbitrary PHP objects. This injection can lead to execution of arbitrary code on the server, compromising confidentiality, integrity, and availability of the site and potentially the underlying host system.

Affected Systems

WordPress sites that have the Novalnet Payment Gateway for WooCommerce plugin installed at version 12.10.3 or earlier are impacted. The affected product is the Novalnet Payment Gateway for WooCommerce, a payment gateway integration plugin for WooCommerce. Only sites running the listed versions of this plugin should assess whether it is deployed and determine the need for remediation.

Risk and Exploitability

The CVSS score of 9.8 classifies the vulnerability as critical, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The issue is not listed in CISA KEV. Attackers can exploit the flaw remotely and without authentication by sending crafted requests to the plugin’s endpoints, so any visitor to a vulnerable site could attempt exploitation. The combination of unauthenticated remote access, high severity, and low exploitation likelihood makes it a high‑priority risk for sites that have not applied the available patch.

Generated by OpenCVE AI on July 21, 2026 at 11:40 UTC.

Remediation

Vendor Solution

Update the WordPress Novalnet Payment Gateway for WooCommerce Plugin to the latest available version (at least 12.10.4).


OpenCVE Recommended Actions

  • Upgrade the Novalnet Payment Gateway for WooCommerce plugin to version 12.10.4 or later.
  • Disable or uninstall the plugin if it is no longer needed to eliminate the attack surface.
  • Configure a web application firewall or server rules to block requests that target the plugin’s vulnerable endpoints and monitor logs for suspicious activity.

Generated by OpenCVE AI on July 21, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Novalnet
Novalnet novalnet Payment Gateway For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Novalnet
Novalnet novalnet Payment Gateway For Woocommerce
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
Title WordPress Novalnet Payment Gateway for WooCommerce plugin <= 12.10.3 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Novalnet Novalnet Payment Gateway For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:09:37.862Z

Reserved: 2026-06-25T08:03:42.566Z

Link: CVE-2026-57677

cve-icon Vulnrichment

Updated: 2026-07-02T12:09:33.647Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:45:03Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data