OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-93624

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Music Player for WooCommerce versions up to 1.9.1 are vulnerable to PHP Object Injection, which could allow an attacker to execute arbitrary code and potentially compromise the web application. This high-severity vulnerability should be prioritized by developers and administrators using the affected plugin to mitigate risks of exploitation and ensure the security of their e-commerce environments.

CVE
CVE-2026-93624
Severity
HIGH
CVSS
7.2
EPSS
0.37%

Original NVD Description

Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.