CVE-2026-1235: Unknown Wp Ecommerce

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

Affected products

  • Unknown Wp Ecommerce: up to and including 3.15.1

Published 2026-02-11. Last modified 2026-06-17.