CVE-2026-96344: WordPress eCommerce Product Catalog plugin <= 3.6.0 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
Affected Software
1 affected component
impleCode eCommerce Product Catalog<=3.6.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress eCommerce Product Catalog pluginto a version that resolves this vulnerability.Fixed in 3.6.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs high privileges in the WordPress site, as indicated by the PR:H vector. The issue is described as involving custom roles, so sites that grant privileged capabilities to custom-role users should review those assignments.
2
Does exploitation require user interaction or special access to the site?
No user interaction is required, and the attack vector is network-accessible. However, the attacker must already hold high privileges.
3
What versions are affected?
impleCode eCommerce Product Catalog versions through 3.6.0 are affected.