CVE-2026-95603: WordPress Reycob Product Import Export plugin <= 2.3.0 - PHP Object Injection vulnerability
Published Sep 23, 2026
·Updated
Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.
Affected Software
1 affected component
Reycob Product Import Export<=2.3.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Reycob Product Import Export pluginto a version that resolves this vulnerability.Fixed in 2.4.0
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Shop Manager privileges in WordPress. The vulnerability is not described as exploitable by unauthenticated or lower-privileged users.
2
Which plugin versions are affected?
Reycob Product Import Export versions 2.3.0 and earlier are affected.
3
What is the potential impact?
The issue is classified as PHP object injection and is rated high severity, with high impacts to confidentiality, integrity, and availability in the provided vector.