PT-2019-8296 · Automattic · Woocommerce

CVE-2017-18356

·

Published

2019-01-15

·

Updated

2024-10-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce plugin versions prior to 3.2.4
Description The issue allows an attack after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker constructs a specifically crafted string that turns into a PHP object injection involving the WC Shortcode Products::get products() function in the includes/shortcodes/class-wc-shortcode-products.php file, which uses cached queries within shortcodes.
Recommendations For versions prior to 3.2.4, update to version 3.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the WC Shortcode Products::get products() function until a patch is available. Additionally, limiting user privileges to below Shop manager may help minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18356

Affected Products

Woocommerce