CRITICAL
payever
CVE published 2026-10-10
CVE-2026-42716
The Payever - WooCommerce Gateway plugin versions up to 4.8.2 are vulnerable to an unauthenticated PHP Object Injection. This critical vulnerability could lead to potential code execution and data breaches on vulnerable WordPress installations. Defenders should assess exposure and apply patches or mitigations to prevent exploitation. The vulnerability has a CVSS score of 9.8, indicating a high severity le [truncated]