Input validation vulnerability in CiyaShop – Multipurpose WooCommerce Theme 4.19.0

The CiyaShop theme for WordPress, which can be used for a variety of purposes, has a security vulnerability. This vulnerability, known as PHP Object Injection, affects all versions up to 4.19.0. It allows attackers to insert malicious code into the theme, potentially giving them access to sensitive information or the ability to delete files. This vulnerability can only be exploited if the website has another plugin or theme that contains a specific type of code called a POP chain.

Detected in:

CiyaShop - Multipurpose WooCommerce Theme open vulnerable versions: >= * <= 4.19.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.