CVE-2026-42718 and CVE-2026-42716: Critical WooCommerce Plugin Vulnerabilities
This text was generated using artificial intelligence (AI).Patchstack identifies two critical vulnerabilities in WooCommerce extensions: CVE-2026-42718 concerns Booster for WooCommerce up to and including version 8.4.0. CVE-2026-42716 concerns Payever – WooCommerce Gateway up to and including version 4.8.2.
Both entries are rated with a CVSS score of 9.8 and are classified as PHP Object Injection through insecure deserialization of the vulnerabilities category CWE-502 According to the published CVSS information, neither permissions nor user interaction are required for the attack.
The Patchstack advisories describe both vulnerabilities as unauthenticated PHP Object Injection. The entries show network access, low attack complexity, and no required privileges.
As of the publication of this post, no patched versions are available for CVE-2026-42718 and CVE-2026-42716.
According to OpenCVE and Vulners, several vulnerabilities have been documented in the Pluggabls Booster product line over the past 24 months, including CVE-2024-12278 (Stored Cross-Site Scripting in Booster for WooCommerce up to and including version 7.2.4) and CVE-2025-39446 (Reflected Cross-Site Scripting in Booster Plus for WooCommerce up to and including version 7.2.4). This context underscores the importance of continuous monitoring of third-party plugins.
Technical Classification: PHP Object Injection
In insecure deserialization, an application processes serialized PHP objects. Attackers may be able to influence this process. The consequences depend on the classes and methods present in the respective system.
As is typical with vulnerabilities of category CWE-502, the following scenarios may arise depending on the classes and methods present in the system:
Remote Code Execution with an existing POP chain,
SQL Injection,
Path Traversal,
Denial of Service.
A POP chain refers to a chain of existing PHP classes and methods that can execute unwanted functions during the processing of a manipulated object. The possibility of remote code execution is thus linked to this technical requirement.
At the time of verification, the NVD analysis for both CVEs was still pending. There is no information available on active exploitation, proof of concept, or specific attacker groups.
Prioritized steps for affected WordPress installations
Organizations should first determine whether the specified plugins are in use within the affected version ranges. The review should include productive WooCommerce installations as well as other publicly accessible WordPress instances.
Cover installations of Booster for WooCommerce up to and including version 8.4.0.
Cover installations of Payever – WooCommerce Gateway up to and including version 4.8.2.
Check for impact and patch status for both vulnerabilities.
Prioritize and mitigate affected systems.
Check WordPress plugin auto-updates and activate if suitable.
If no official patch is available yet, activate Patchstack vPatch as a virtual patch measure.
Establish continuous monitoring of vulnerabilities and software dependencies.
An update to a version above 8.4.0 for Booster for WooCommerce is planned as soon as a patch is released. For Payever – WooCommerce Gateway, an update to a version above 4.8.2 is similarly planned as soon as a patch is released.
DACH relevance for shop operators
For DACH operators of WooCommerce shops processing personal customer data, in the event of successful exploitation, the reporting obligation according to GDPR Art. 33 should be checked: It specifies a 72-hour deadline for notifying the competent supervisory authority. For NIS-2-obligated entities in Germany and Austria, continuous monitoring of third-party plugins in use is part of the technical minimum requirements. Swiss shop operators are subject to the revised Information Security Act (ISG) with a reporting obligation to the BACS.
Visibility of publicly accessible shop systems with LocateRisk
WooCommerce extensions are operated under a customer domain as a web application. With Booster for WooCommerce, indications of the software in use may be recognizable externally via HTTP response headers, HTML markup, or plugin paths such as /wp-content/plugins/woocommerce-jetpack/ from the outside.
LocateRisk supports External Attack Surface Management by providing visibility on publicly accessible assets and externally recognizable web technologies. This allows shop domains and other external systems to be included in the evaluation of a vulnerability report. The platform makes exposure and software in use visible; this does not necessarily confirm the specifically vulnerable version.
C-VRM complements this perspective with reports on critical vulnerabilities in software vendors or changes in their security level. The technical review of one's own externally accessible systems remains separate and should consider the patch status of the actually used extensions.
Am I affected?
Affected are Booster for WooCommerce and Payever – WooCommerce Gateway in the versions mentioned above. Those who want to know whether Booster for WooCommerce and Payever – WooCommerce Gateway are even visible in their external accessible infrastructure can check the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
PHP Object Injection (CWE-502) refers to a vulnerability where an application processes externally transmitted, serialized PHP objects without properly validating them. Attackers can inject manipulated objects, potentially triggering severe consequences depending on the PHP classes present in the system. Since neither permissions nor user interaction is required for the existing vulnerabilities, the attack potential is particularly high.
This affects Booster for WooCommerce (Pluggabl) in all versions up to and including 8.4.0 (CVE-2026-42718, CVSS 9.8) as well as Payever – WooCommerce Gateway in all versions up to and including 4.8.2 (CVE-2026-42716, CVSS 9.8). Both vulnerabilities allow unauthenticated attacks without user interaction.
At the time of publication of this post, no patched versions have been released for CVE-2026-42718 and CVE-2026-42716. Affected installations should be secured until an official update is available using Patchstack vPatch or by disabling the affected plugins.
As of: October 10, 2026. This article is for general informational purposes and does not constitute legal, security, or action advice in individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee the accuracy, correctness, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-42718
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.