OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-94677

HIGH · CVSS 7.2 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability in Kadence WooCommerce Email Designer versions up to 1.5.19.1 allows for PHP Object Injection, which could enable an attacker to execute arbitrary code on the server. This poses a significant risk to any e-commerce platform utilizing the affected plugin, potentially compromising sensitive customer data and the integrity of the application. E-commerce site administrators and developers using this plugin should prioritize immediate updates to mitigate this high-severity risk.

CVE
CVE-2026-94677
Severity
HIGH
CVSS
7.2
EPSS
0.40%

Original NVD Description

Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.