CyberRota Analysis
AI-GeneratedA PHP Object Injection vulnerability exists in the Cost of Goods plugin for WooCommerce versions up to 3.5.2, allowing attackers to exploit the shop manager functionality. This could lead to unauthorized access and manipulation of sensitive data, potentially compromising the integrity of the e-commerce platform. WooCommerce users running affected versions should prioritize immediate updates to mitigate the risk.
CVE
CVE-2026-93771
Severity
HIGH
CVSS
7.2
EPSS
0.37%
Original NVD Description
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.