Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A PHP Object Injection vulnerability in the WooCommerce Infinite Scroll and Ajax Pagination WordPress plugin (versions 1.8 and below) allows authenticated attackers with minimal privileges to inject arbitrary PHP objects. If any other installed plugin or theme contains a usable exploit chain, this vulnerability can escalate to remote code execution, file deletion, or sensitive data theft. WooCommerce-based e-commerce sites running this plugin should treat this as a priority remediation item. 72-hour remediation window recommended for patch deployment.

Author

Tech Jacks Solutions