<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Mirasvit</title><description>Actively exploited vulnerabilities affecting Mirasvit products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/mirasvit.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-45247 — Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-45247</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-45247</guid><description>This vulnerability allows an unauthenticated attacker to send a specially crafted serialized PHP object via the CacheWarmer cookie, triggering PHP deserialization flaws that result in full remote code execution on the server. No login or privileges are required, meaning any internet-exposed Magento store running this extension is at risk of complete server compromise. The ease of exploitation and severity of the outcome make this a critical priority for any organization running the affected plugin.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>Mirasvit</category><category>Mirasvit Full Page Cache Warmer</category></item></channel></rss>