


Perceptive Security
SOC/SIEM Consultancy

Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 14:04:36
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
CVE-2026-57677 describes an unauthenticated PHP Object Injection vulnerability affecting the Novalnet Payment Gateway plugin for WooCommerce in versions up to and including 12.10.3. This vulnerability allows unauthenticated attackers to inject PHP objects, which could potentially lead to remote code execution, file manipulation, or other serious impacts depending on available POP chains in the environment. The flaw resides in the WooCommerce payment gateway plugin developed by Novalnet, a payment service provider. Because no authentication is required to exploit this vulnerability, the attack surface is significant for any WordPress site using the affected plugin version. The issue has been documented by both NVD and Patchstack, indicating broad awareness in the security community. Site administrators running WooCommerce with the Novalnet payment gateway should update to a patched version immediately. The vulnerability is rated as high severity given the unauthenticated nature of the exploit vector.
Technical details
Mitigation steps:
Affected products:
Novalnet Payment Gateway for WooCommerce <= 12.10.3
WordPress WooCommerce
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-57677
https://patchstack.com/database/wordpress/plugin/woocommerce-novalnet-gateway/vulnerability/wordpress-novalnet-payment-gateway-for-woocommerce-plugin-12-10-3-php-object-injection-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
