OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-93651

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability in WooCommerce versions up to 2.1.2 allows for PHP Object Injection, which can be exploited to execute arbitrary PHP code on the server. This poses a significant risk to the integrity and confidentiality of the affected systems, potentially leading to unauthorized access or data manipulation. E-commerce operators using these versions should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-93651
Severity
HIGH
CVSS
7.2
EPSS
0.37%

Original NVD Description

Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.