CVE-2026-42718 and CVE-2026-42716: Critical WooCommerce Plugin Vulnerabilities

This text was generated using artificial intelligence (AI).Patchstack identifies two critical vulnerabilities in WooCommerce extensions: CVE-2026-42718 concerns Booster for WooCommerce up to and including version 8.4.0. CVE-2026-42716 concerns Payever – WooCommerce Gateway up to and including version 4.8.2.

Both entries are rated with a CVSS score of 9.8 and are classified as PHP Object Injection through insecure deserialization of the vulnerabilities category CWE-502 According to the published CVSS information, neither permissions nor user interaction are required for the attack.

Are my systems affected? Check now →