Description
Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Shop manager PHP Object Injection is present in WordPress WooCommerce Multilingual & Multicurrency plugin version 5.5.8 and earlier. The flaw allows an attacker to instantiate arbitrary PHP objects via crafted serialized data, which can lead to remote code execution on the underlying web server. This is a classic case of CWE‑502, an insecure deserialization vulnerability that undermines input validation and can compromise the entire application.

Affected Systems

Amir Helzer’s WooCommerce Multilingual & Multicurrency plugin, a popular multilingual e‑commerce add‑on for WordPress, is affected in all releases up to 5.5.8. The advisory recommends updating to at least version 5.6.3, which removes the unsafe deserialization logic. Sites that host the shop manager interface using these older plugin versions are at risk.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity, and while the EPSS score is currently unavailable, the lack of a CISA KEV listing does not reduce the potential for exploitation. The attack vector is inferred to be remote, requiring access to the shop manager endpoints to submit malicious serialized payloads. Successful exploitation can provide the attacker with full code execution privileges, making remediation a high priority for all merchants running the vulnerable plugin.

Generated by OpenCVE AI on October 10, 2026 at 21:27 UTC.

Remediation

Vendor Solution

Update the WordPress WooCommerce Multilingual & Multicurrency plugin to the latest available version (at least 5.6.3).


OpenCVE Recommended Actions

  • Update the plugin to version 5.6.3 or later.
  • If a quick update is not possible, temporarily disable or remove the WooCommerce Multilingual & Multicurrency plugin from the WordPress site.
  • Implement input validation or deploy a web application firewall to block malicious serialized payloads targeting the shop manager endpoints.

Generated by OpenCVE AI on October 10, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions.
Title WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.8 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:36:06.188Z

Reserved: 2026-07-13T06:15:19.260Z

Link: CVE-2026-62130

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:44.913

Modified: 2026-10-10T20:16:44.913

Link: CVE-2026-62130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T21:30:17Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data