top of page
perceptive_background_267k.jpg

Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.

Published:

1 juli 2026 om 22:00:00

Alert date:

2 juli 2026 om 14:04:36

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

CVE-2026-57677 describes an unauthenticated PHP Object Injection vulnerability affecting the Novalnet Payment Gateway plugin for WooCommerce in versions up to and including 12.10.3. This vulnerability allows unauthenticated attackers to inject PHP objects, which could potentially lead to remote code execution, file manipulation, or other serious impacts depending on available POP chains in the environment. The flaw resides in the WooCommerce payment gateway plugin developed by Novalnet, a payment service provider. Because no authentication is required to exploit this vulnerability, the attack surface is significant for any WordPress site using the affected plugin version. The issue has been documented by both NVD and Patchstack, indicating broad awareness in the security community. Site administrators running WooCommerce with the Novalnet payment gateway should update to a patched version immediately. The vulnerability is rated as high severity given the unauthenticated nature of the exploit vector.

Technical details

Mitigation steps:

Affected products:

Novalnet Payment Gateway for WooCommerce <= 12.10.3
WordPress WooCommerce

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page