CVE-2023-49777: WordPress YITH WooCommerce Product Add-Ons Plugin <= 4.3.0 is vulnerable to PHP Object Injection
Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49777?
CVE-2023-49777 is classified as a high severity vulnerability due to its potential for exploitation through deserialization of untrusted data.
How do I fix CVE-2023-49777?
The recommended fix for CVE-2023-49777 is to upgrade YITH WooCommerce Product Add-Ons to version 4.3.1 or higher.
What versions are affected by CVE-2023-49777?
CVE-2023-49777 affects all versions of YITH WooCommerce Product Add-Ons from n/a up to and including 4.3.0.
What type of vulnerability is CVE-2023-49777?
CVE-2023-49777 is a deserialization of untrusted data vulnerability, which can lead to remote code execution.
Is CVE-2023-49777 being actively exploited?
While there are no specific reports of active exploitation for CVE-2023-49777, its severity suggests that it should be addressed promptly.