OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-93771

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A PHP Object Injection vulnerability exists in the Cost of Goods plugin for WooCommerce versions up to 3.5.2, allowing attackers to exploit the shop manager functionality. This could lead to unauthorized access and manipulation of sensitive data, potentially compromising the integrity of the e-commerce platform. WooCommerce users running affected versions should prioritize immediate updates to mitigate the risk.

CVE
CVE-2026-93771
Severity
HIGH
CVSS
7.2
EPSS
0.37%

Original NVD Description

Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.