Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sbthemes
Sbthemes woocommerce Infinite Scroll And Ajax Pagination Wordpress Wordpress wordpress |
|
| Vendors & Products |
Sbthemes
Sbthemes woocommerce Infinite Scroll And Ajax Pagination Wordpress Wordpress wordpress |
Fri, 29 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. This is due to deserialization of untrusted data supplied via the import configuration feature without capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No POP chain is present within the vulnerable plugin itself, but if a POP chain is present via an additional plugin or theme installed on the target system, it could allow an attacker to delete arbitrary files, retrieve sensitive data, or execute code. | |
| Title | WooCommerce Infinite Scroll and Ajax Pagination <= 1.8 - Authenticated (Subscriber+) PHP Object Injection | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-29T10:06:43.473Z
Reserved: 2025-10-20T20:07:27.819Z
Link: CVE-2025-11993
Updated: 2026-05-29T10:06:38.969Z
Status : Deferred
Published: 2026-05-29T07:16:13.730
Modified: 2026-05-29T13:09:05.450
Link: CVE-2025-11993
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:47:33Z