CVE-2024-11465 Details
Description
The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input in the 'yikes_woo_products_tabs' post meta parameter. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
A PHP Object Injection vulnerability has been identified in the Yikes Custom Product Tabs for WooCommerce plugin for WordPress, affecting all versions through 1.8.5. The vulnerability arises from the deserialization of untrusted data in the 'yikes_woo_products_tabs' post meta parameter. This flaw allows authenticated attackers with Shop Manager-level access or higher to inject a PHP object. While the vulnerable plugin does not have a known object injection chain, such a chain could potentially be exploited if an additional plugin or theme on the target system provides one, possibly leading to arbitrary file deletion, sensitive data exposure, or code execution.
Users are advised to update the Yikes Custom Product Tabs for WooCommerce plugin to version 1.8.6 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| yikesinc custom product tabs for woocommerce | <= 1.8.5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | CVE Modified | [email protected] |
| Feb 25, 2025 | Initial Analysis | [email protected] |
| Jan 7, 2025 | New CVE Received | [email protected] |