PT-2026-20657 · WordPress · Yith Woocommerce Compare

Mcdruid

·

Published

2026-02-19

·

Updated

2026-02-19

·

CVE-2026-22333

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YITH WooCommerce Compare versions through 3.6.0
Description The YITH WooCommerce Compare plugin contains a flaw related to the deserialization of untrusted data, which can lead to object injection. This issue allows for potential compromise of the system through malicious data.
Recommendations Update YITH WooCommerce Compare to a version later than 3.6.0.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-22333

Affected Products

Yith Woocommerce Compare