Novalnet · Novalnet Payment Gateway For Woocommerce · CVE-2026-57677
**Name of the Vulnerable Software and Affected Versions**
Novalnet Payment Gateway for WooCommerce versions prior to 12.10.4
**Description**
The plugin is susceptible to PHP Object Injection, a condition where an application deserializes untrusted input, allowing an attacker to inject a PHP Object. While no native POP chain (a sequence of gadgets used to achieve code execution) is present in the software, the presence of a POP chain in other installed plugins or themes could enable an unauthenticated attacker to execute code, retrieve sensitive data, or delete arbitrary files.
**Recommendations**
Update to a version newer than 12.10.3.