← WordPress Vulnerabilities
WordPress security by component

Product Addons and Product Options With Custom Fields

Product Addons and Product Options With Custom Fields is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 22, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: product-addons-and-product-options-with-custom-fields

CVE-2026-12968: Product Addons permits unauthenticated malicious SVG uploads

Product Addons and Product Options With Custom Fields before 1.6.15 exposes a file-upload path without authentication and accepts SVG content that is served inline. An attacker can upload an SVG containing script; the script executes in the affected site's origin when an administrator or another visitor opens the uploaded file.

PublishedJul 22, 2026
Known safe version1.6.15
Safe version
Jul 22, 2026 CVE-2026-12968
Product Addons permits unauthenticated malicious SVG uploads
Product Addons and Product Options With Custom Fields before 1.6.15 exposes a file-upload path without authentication and accepts SVG content that is served inline. An attacker can upload an SVG containing script; the script executes in the affected site's origin when an administrator or another visitor opens the uploaded file.
1.6.15
CVE8.8
NVDPending