
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22354 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the Dotstore WooCommerce Category Banner Management WordPress plugin. It affects all versions through 2.5.3 (initially reported as through 2.5.1) and allows authenticated attackers with low privileges (Contributor/Developer role) to inject malicious PHP objects. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Patchstack, Feedly).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The plugin fails to safely handle user-supplied serialized data, allowing an authenticated attacker to pass a crafted PHP object through a vulnerable input that is subsequently deserialized server-side. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress environment or installed plugins, this can be leveraged to achieve code injection, SQL injection, path traversal, or denial of service. Exploitation requires network access and a low-privilege authenticated account (Contributor or Developer role), with no user interaction needed (Patchstack, Feedly).
Successful exploitation can result in full confidentiality, integrity, and availability compromise of the affected WordPress/WooCommerce site, depending on the availability of a POP chain in the target environment. An attacker could achieve remote code execution, unauthorized data access or exfiltration, database manipulation, or complete system takeover. The impact extends to all data processed by the affected WordPress instance, including customer and order data stored in WooCommerce (Patchstack, Feedly).
As of the time of reporting, no public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation. The EPSS score is 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this type (CVSS 8.8, mass-exploitable) are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack, Feedly).
O: or a: in request bodies).bash, curl, wget) following plugin interaction.No official patch from the vendor (Dotstore) was available at the time of disclosure; the vulnerable versions span through 2.5.3. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Recommended actions include: (1) disabling or removing the plugin until a patched version is available; (2) implementing strict access controls to limit Contributor/Developer role assignments; (3) applying the principle of least privilege to all user accounts; and (4) monitoring for suspicious activity from accounts with editing privileges (Patchstack, Feedly).
Patchstack, which credited researcher Muhammad Yudha - DJ for the discovery (reported November 30, 2025), classified this as a medium-priority vulnerability and noted it is the type commonly leveraged in mass-exploit campaigns against WordPress sites. Wordfence included this CVE in its weekly WordPress vulnerability report for the period of February 16–22, 2026, indicating broader community awareness (Wordfence Blog, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."