Input validation vulnerability in Custom Product Tabs Lite for WooCommerce 1.9.0

The Custom Product Tabs Lite for WooCommerce plugin for WordPress has a security issue that makes it vulnerable to a type of attack called PHP Object Injection. This can happen when the plugin receives input from a parameter called ‘frs_woo_product_tabs’ that is not trustworthy. This allows hackers who are logged in with Shop Manager-level access or higher to inject a PHP Object, which could potentially cause harm to the website. There is currently no known way for the attacker to access the system, but if there is another plugin or theme installed that is also vulnerable, it could allow the attacker to delete files, access private information, or run code without permission.

Detected in:

Custom Product Tabs Lite for WooCommerce fixed vulnerable versions: >= * <= 1.9.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.