Barn2 Media · Woocommerce Products Filter · CVE-2026-40725
**Name of the Vulnerable Software and Affected Versions**
WooCommerce Product Filters versions prior to 2.0.6
**Description**
An unauthenticated PHP Object Injection issue exists in the software. PHP Object Injection occurs when user-supplied input is passed to the `unserialize()` function without proper validation, potentially allowing an attacker to manipulate objects and execute arbitrary code.
**Recommendations**
Update to version 2.0.6 or later.