CVE-2026-42718: WordPress Booster for WooCommerce plugin <= 8.4.0 - PHP Object Injection vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated PHP Object Injection in Booster for WooCommerce <= 8.4.0 versions.
Affected Software
1 affected component
WordPress Booster for WooCommerce<=8.4.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Booster for WooCommerceto a version that resolves this vulnerability.Fixed in 8.5.0
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are exposed?
WordPress sites running Booster for WooCommerce version 8.4.0 or earlier are affected. The network attack vector indicates that a remotely reachable site using an affected version is in scope.
2
Does an attacker need an account or user interaction to exploit this?
No. The vulnerability is unauthenticated, requires no privileges, has low attack complexity, and does not require user interaction.
3
How can I determine whether my site is affected?
Check the installed version of the Booster for WooCommerce plugin. Versions 8.4.0 and earlier are affected.