Product Configurator for WooCommerce <= 1.7.5 - Authenticated (Shop Manager+) PHP Object Injection via Configurator Data

Medium 6.6 CWE-502Fixed in 1.7.6
ID
WPSEC-2026-0507
Plugin
Product Configurator for WooCommerce (product-configurator-for-woocommerce)
Affected
all versions before 1.7.6
Remediation
Update to 1.7.6 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-502
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Product Configurator for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Product Configurator for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.5 via deserialization of untrusted input in the configurator data. The configurator save AJAX action accepts string values instead of only the expected arrays and stores them in product meta, and the stored value is later passed to maybe_unserialize() whenever the product's configurator data is read, including when visitors load the product configurator. This makes it possible for authenticated attackers with permission to edit products, such as Shop Manager-level access and above, to inject a PHP object. No known POP chain is present in the vulnerable software itself; if a POP chain is present via another plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0