woocommerce/email-editor is vulnerable to Deserialization of Untrusted Data
40
Medium Risk
Affected versions of this package are vulnerable to callback replacement attacks via deserialization in the Personalization_Tag class due to the absence of a preventive method. This flaw allows attackers to craft malicious serialized data that replaces legitimate callbacks with arbitrary code. The exploitation occurs when the application processes untrusted serialized input, enabling attackers to hijack callback functions and execute unauthorized actions.
You are affected if you are using a version that falls within the vulnerable range.
woocommerce/email-editor is vulnerable to Deserialization of Untrusted Data in versions 1.0.0 - 1.7.0.
Upgrade the woocommerce/email-editor library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant