OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-94390

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the Hide Shipping Method plugin for WooCommerce versions 1.5.4 and earlier, allowing for PHP Object Injection through improper handling of user input. This could enable an attacker to execute arbitrary PHP code, potentially compromising the integrity and security of the affected e-commerce sites. WooCommerce site administrators using the vulnerable plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-94390
Severity
HIGH
CVSS
7.2
EPSS
0.37%

Original NVD Description

Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.