CVE-2024-50416: WordPress WPC Shop as a Customer for WooCommerce plugin <= 1.2.6 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through <= 1.2.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50416?
CVE-2024-50416 is classified as a medium severity vulnerability affecting the WPC Shop as a Customer for WooCommerce plugin.
How do I fix CVE-2024-50416?
To fix CVE-2024-50416, update the WPC Shop as a Customer for WooCommerce plugin to version 1.2.7 or later.
Which versions of WPC Shop as a Customer for WooCommerce are affected by CVE-2024-50416?
CVE-2024-50416 affects all versions of WPC Shop as a Customer for WooCommerce from n/a through 1.2.6.
What type of vulnerability is CVE-2024-50416?
CVE-2024-50416 is a Deserialization of Untrusted Data vulnerability that allows for Object Injection.
Is there a workaround for CVE-2024-50416?
There is no documented workaround for CVE-2024-50416; updating the plugin is the recommended action.