Impact
The Hide Shipping Method For WooCommerce plugin versions up to 1.5.4 contain a PHP Object Injection vulnerability that allows an attacker to inject malicious serialized objects. If exploited, the attacker can execute arbitrary PHP code on the affected WordPress site, compromising confidentiality, integrity and availability. The weakness falls under CWE-502.
Affected Systems
WordPress sites that have the Hide Shipping Method For WooCommerce plugin from the vendor Dotstore installed at version 1.5.4 or earlier. No specific operating system or WordPress core version is listed as affected, so any site hosting the vulnerable plugin is at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity level. Although the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the possibility of remote code execution via web-based input makes the risk significant. The likely attack vector is through a crafted request to the plugin’s editor interface or any exposed endpoint that accepts serialized input.
OpenCVE Enrichment