Intel

AIKIDO-2025-10699

woocommerce/email-editor is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted Data Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 10, 2025

40

Medium Risk

This Affects:

PHPwoocommerce/email-editor
1.0.0 - 1.7.0
Fixed in 1.8.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to callback replacement attacks via deserialization in the Personalization_Tag class due to the absence of a preventive method. This flaw allows attackers to craft malicious serialized data that replaces legitimate callbacks with arbitrary code. The exploitation occurs when the application processes untrusted serialized input, enabling attackers to hijack callback functions and execute unauthorized actions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

woocommerce/email-editor is vulnerable to Deserialization of Untrusted Data in versions 1.0.0 - 1.7.0.

How to fix this

Upgrade the woocommerce/email-editor library to the patch version.