CVE-2026-23971: WordPress WoodMart theme <= 8.3.8 - PHP Object Injection vulnerability
Published Mar 25, 2026
·Updated
Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects WoodMart: from n/a through <= 8.3.8.
Affected Software
1 affected component
Xtemos WoodMart<=8.3.8
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-23971?
CVE-2026-23971 has a severity rating that indicates it is a significant vulnerability due to its potential for PHP Object Injection.
2
How do I fix CVE-2026-23971?
To fix CVE-2026-23971, update the WoodMart theme to a version higher than 8.3.8.
3
What are the risks associated with CVE-2026-23971?
The risks of CVE-2026-23971 include potential remote code execution due to untrusted data deserialization.
4
Which versions of WoodMart are affected by CVE-2026-23971?
CVE-2026-23971 affects all versions of the WoodMart theme up to and including version 8.3.8.
5
Is there a patch available for CVE-2026-23971?
Yes, the patch for CVE-2026-23971 is included in the WoodMart theme updates beyond version 8.3.8.