CVE-2026-94390: WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.4 - PHP Object Injection vulnerability
Published Oct 1, 2026
·Updated
Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.
Affected Software
1 affected component
WordPress Hide Shipping Method For WooCommerce<=1.5.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Hide Shipping Method For WooCommerceto a version that resolves this vulnerability.Fixed in 1.5.5
Event History
Oct 1, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Editor-level privileges. The attack can be performed remotely and does not require user interaction.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can affect confidentiality, integrity, and availability, all rated High in the supplied severity vector.