Output validation vulnerability in UltimateWoo – The Ultimate WooCommerce Plugin with Unlimited Usage 0.1.10

The UltimateWoo plugin for WordPress is vulnerable to a security issue called PHP Object Injection. This affects versions up to, and including, 0.1.10. An attacker can insert malicious code into the vulnerable parameter ‘opauth’ which could allow them to delete files, steal data, or run code on the target system. If the target system has additional plugins or themes installed, this could make the attack even more dangerous.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.