OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-95603

HIGH · CVSS 7.2 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Reycob Product Import Export plugin versions up to 2.3.0 are vulnerable to PHP Object Injection, which could allow an attacker to execute arbitrary code on the server. This high-severity vulnerability poses a significant risk to any systems utilizing the affected plugin, particularly in e-commerce environments. Organizations using this plugin should prioritize immediate updates or mitigations to safeguard against potential exploitation.

CVE
CVE-2026-95603
Severity
HIGH
CVSS
7.2
EPSS
0.40%

Original NVD Description

Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.