CVE-2017-18356: Code Injection
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WCShortcodeProducts::getproducts() use of cached queries within shortcodes.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18356?
CVE-2017-18356 is a vulnerability in the Automattic WooCommerce plugin before version 3.2.4 for WordPress.
What is the severity of CVE-2017-18356?
The severity of CVE-2017-18356 is high (CVSS score of 8.8).
How can an attacker exploit CVE-2017-18356?
An attacker can exploit CVE-2017-18356 by gaining access to the target site with a user account that has at least Shop manager privileges and constructing a specifically crafted string that will result in PHP object injection.
What is the affected software of CVE-2017-18356?
The affected software of CVE-2017-18356 is the Automattic WooCommerce plugin before version 3.2.4 for WordPress.
How can I fix CVE-2017-18356?
You can fix CVE-2017-18356 by updating your Automattic WooCommerce plugin to version 3.2.4 or higher.