Description
WordPress Plugin WooCommerce is prone to a vulnerability that lets remote attackers inject arbitrary code because the application fails to sanitize user-supplied input before being passed to the maybe_unserialize() function. Attackers can possibly exploit this issue to download any file on the vulnerable server. WordPress Plugin WooCommerce version 2.3.10 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.11 or latest
References
https://blog.sucuri.net/2015/06/security-advisory-object-injection-vulnerability-in-woocommerce.html
Related Vulnerabilities
WordPress Plugin Custom Login Redirect Cross-Site Request Forgery (1.0.0)
WordPress Plugin MathJax-LaTeX Cross-Site Request Forgery (1.1)
WordPress Plugin Twitter Cards Meta Multiple Vulnerabilities (2.4.5)
PHP Improper Preservation of Permissions Vulnerability (CVE-2020-7063)
WordPress Plugin NextGEN Gallery-WordPress Gallery Security Bypass (3.1.6)