CVE-2023-32795: WordPress WooCommerce Product Add-ons Plugin <= 6.1.3 is vulnerable to PHP Object Injection
Published Dec 28, 2023
·Updated
Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from n/a through 6.1.3.
Affected Software
1 affected component
WooCommerce Product Addons Wordpress<=6.1.3
Remediation
Information
Update to 6.2.0 or a higher version.
Event History
Dec 28, 2023
CVE Published
via MITRE·10:43 AM
Data Sourced
via MITRE·10:43 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-32795?
CVE-2023-32795 is classified as a high-severity vulnerability due to its potential for deserialization of untrusted data.
2
How do I fix CVE-2023-32795?
To fix CVE-2023-32795, update WooCommerce Product Add-Ons to version 6.1.4 or later.
3
What versions are affected by CVE-2023-32795?
CVE-2023-32795 affects WooCommerce Product Add-Ons versions up to and including 6.1.3.
4
Can CVE-2023-32795 lead to code execution?
Yes, CVE-2023-32795 can potentially lead to remote code execution if exploited by an attacker.
5
Is user authentication required to exploit CVE-2023-32795?
Yes, exploitation of CVE-2023-32795 requires authenticated access to the affected WordPress site.