CVE-2026-22354: WordPress Woocommerce Category Banner Management plugin <= 2.5.1 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for-woocommerce allows Object Injection.This issue affects Woocommerce Category Banner Management: from n/a through <= 2.5.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22354?
CVE-2026-22354 is considered a critical vulnerability due to its potential for PHP Object Injection leading to remote code execution.
How do I fix CVE-2026-22354?
To fix CVE-2026-22354, update the Woocommerce Category Banner Management plugin to version 2.5.2 or later.
What kind of vulnerability is CVE-2026-22354?
CVE-2026-22354 is a PHP Object Injection vulnerability resulting from the deserialization of untrusted data.
Who is affected by CVE-2026-22354?
Any WordPress site using the Woocommerce Category Banner Management plugin version 2.5.1 or earlier is affected by CVE-2026-22354.
What can attackers achieve with CVE-2026-22354?
Attackers can exploit CVE-2026-22354 to execute arbitrary PHP code on vulnerable WordPress installations.