Impact
Shop manager PHP Object Injection is present in WordPress WooCommerce Multilingual & Multicurrency plugin version 5.5.8 and earlier. The flaw allows an attacker to instantiate arbitrary PHP objects via crafted serialized data, which can lead to remote code execution on the underlying web server. This is a classic case of CWE‑502, an insecure deserialization vulnerability that undermines input validation and can compromise the entire application.
Affected Systems
Amir Helzer’s WooCommerce Multilingual & Multicurrency plugin, a popular multilingual e‑commerce add‑on for WordPress, is affected in all releases up to 5.5.8. The advisory recommends updating to at least version 5.6.3, which removes the unsafe deserialization logic. Sites that host the shop manager interface using these older plugin versions are at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, and while the EPSS score is currently unavailable, the lack of a CISA KEV listing does not reduce the potential for exploitation. The attack vector is inferred to be remote, requiring access to the shop manager endpoints to submit malicious serialized payloads. Successful exploitation can provide the attacker with full code execution privileges, making remediation a high priority for all merchants running the vulnerable plugin.
OpenCVE Enrichment