PatchSiren cyber security CVE debrief
CVE-2026-40725 Barn2 Media Ltd CVE debrief
A critical vulnerability, CVE-2026-40725, was disclosed in the WooCommerce Product Filters plugin, affecting versions prior to 2.0.6. This vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to severe consequences, including code execution and data breaches. With a CVSS score of 9.8, this vulnerability is considered critical. Administrators of affected systems should prioritize patching to mitigate potential risks.
- Vendor
- Barn2 Media Ltd
- Product
- WooCommerce Product Filters
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and security teams responsible for WordPress installations with the WooCommerce Product Filters plugin should be aware of this vulnerability. Given its critical severity and potential for exploitation, immediate attention is necessary to prevent potential attacks.
Technical summary
CVE-2026-40725 is an unauthenticated PHP Object Injection vulnerability in the WooCommerce Product Filters plugin. This vulnerability exists in versions prior to 2.0.6 and is characterized by its high CVSS score of 9.8, indicating a critical severity level. The vulnerability allows attackers to inject PHP objects without authentication, which could lead to arbitrary code execution and other malicious activities.
Defensive priority
High
Recommended defensive actions
- Update the WooCommerce Product Filters plugin to version 2.0.6 or later.
- Review and monitor plugin and system logs for suspicious activity.
- Implement additional security measures, such as web application firewalls (WAFs) and intrusion detection systems.
- Regularly update and patch all WordPress plugins and themes.
- Consider implementing a vulnerability management program.
- Limit access to sensitive areas of the WordPress installation.
- Monitor for and respond to potential exploitation attempts.
Evidence notes
The CVE-2026-40725 vulnerability was disclosed by Patchstack, as indicated by the reference link provided. The vulnerability's details were sourced from official CVE and NVD records, ensuring accuracy and reliability.
Official resources
-
CVE-2026-40725 CVE record
CVE.org
-
CVE-2026-40725 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
public