Yikes Custom Product Tabs for WooCommerce PHP Object Injection Vulnerability

Vulnerability

A PHP Object Injection vulnerability has been identified in the Yikes Custom Product Tabs for WooCommerce plugin for WordPress, affecting all versions through 1.8.5. The vulnerability arises from the deserialization of untrusted data in the 'yikes_woo_products_tabs' post meta parameter. This flaw allows authenticated attackers with Shop Manager-level access or higher to inject a PHP object. While the vulnerable plugin does not have a known object injection chain, such a chain could potentially be exploited if an additional plugin or theme on the target system provides one, possibly leading to arbitrary file deletion, sensitive data exposure, or code execution.

Impact

Exploitation of this vulnerability could result in PHP Object Injection, allowing for the injection of malicious objects that could be exploited if a suitable payload execution chain is available.

Reproduction

To reproduce this vulnerability, an authenticated user with Shop Manager-level access or higher can send a request that includes a crafted 'yikes_woo_products_tabs' post meta parameter. The untrusted input will be deserialized by the plugin, leading to PHP Object Injection.

Remediation

Users are advised to update the Yikes Custom Product Tabs for WooCommerce plugin to version 1.8.6 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
10.0
exploitability
6.4
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.