{
 "id": "WPSEC-2026-0507",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0507/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0507/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0507/index.md",
 "title": "Product Configurator for WooCommerce <= 1.7.5 - Authenticated (Shop Manager+) PHP Object Injection via Configurator Data",
 "description": "The Product Configurator for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.5 via deserialization of untrusted input in the configurator data. The configurator save AJAX action accepts string values instead of only the expected arrays and stores them in product meta, and the stored value is later passed to maybe_unserialize() whenever the product's configurator data is read, including when visitors load the product configurator. This makes it possible for authenticated attackers with permission to edit products, such as Shop Manager-level access and above, to inject a PHP object. No known POP chain is present in the vulnerable software itself; if a POP chain is present via another plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.",
 "plugin": {
  "slug": "product-configurator-for-woocommerce",
  "name": "Product Configurator for WooCommerce",
  "full_name": "Product Configurator for WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/product-configurator-for-woocommerce/",
  "advisories_url": "https://wpsec.com/vuln/plugin/product-configurator-for-woocommerce/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/product-configurator-for-woocommerce"
 },
 "type": "OBJECT INJECTION",
 "cwe": [
  "CWE-502"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.6,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.7.6",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.7.6"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.7.6",
 "remediation": "Update to 1.7.6 or later.",
 "fix_released": "2026-10-05T19:37:30+00:00",
 "published": "2026-10-07T11:46:41+00:00",
 "updated": "2026-10-07T10:53:26.499158+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0507/",
  "https://plugins.svn.wordpress.org/product-configurator-for-woocommerce/tags/1.7.6/",
  "https://wordpress.org/plugins/product-configurator-for-woocommerce/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/product-configurator-for-woocommerce",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}