Input validation vulnerability in CiyaShop – Multipurpose WooCommerce Theme 4.18.0

The CiyaShop theme for WordPress, up to and including version 4.18.0, has a security vulnerability called PHP Object Injection. This means that if someone who is not authorized tries to use the theme, they can inject a piece of code called a PHP Object. This could be dangerous because it can allow the attacker to delete important files, see private information, or even run their own code. It is possible for this vulnerability to be used if there is another plugin or theme installed on the website, but there is no known way to do this without any additional software.

Detected in:

CiyaShop - Multipurpose WooCommerce Theme open vulnerable versions: >= * <= 4.18.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.