PatchSiren cyber security CVE debrief
CVE-2026-12968 Product Addons and Product Options With Custom Fields CVE debrief
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 has an unauthenticated file-upload endpoint that accepts SVG files. These files are stored and served inline, allowing an attacker to upload a malicious SVG with an embedded script. This script can execute in the session of any user, such as an administrator, who later opens the file. The vulnerability affects users of the plugin, particularly those with versions before 1.6.15. Administrators and users who may interact with uploaded SVG files are at risk. Limited source detail is provided, and defenders should verify the vulnerability with official sources and assess their exposure.
- Vendor
- Product Addons and Product Options With Custom Fields
- Product
- Product Addons and Product Options With Custom Fields WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of the Product Addons and Product Options With Custom Fields WordPress plugin, particularly those with versions before 1.6.15, should be aware of this vulnerability. Administrators and users who may interact with uploaded SVG files are at risk. They should review the official CVE record and NVD detail for more information and take necessary defensive measures.
Technical summary
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline. This allows an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file. The vulnerability affects users of the plugin, particularly those with versions before 1.6.15. Administrators and users who may interact with uploaded SVG files are at risk.
Defensive priority
High priority should be given to updating the Product Addons and Product Options With Custom Fields WordPress plugin to version 1.6.15 or later. Additionally, monitoring for suspicious SVG uploads and ensuring proper validation of uploaded files are crucial defensive measures. Review compensating controls for exposed systems while remediation is scheduled and verified.
Recommended defensive actions
- Update the Product Addons and Product Options With Custom Fields WordPress plugin to version 1.6.15 or later.
- Monitor for suspicious SVG uploads.
- Ensure proper validation of uploaded files.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
Evidence for this vulnerability comes from the NVD and a source reference from WPScan. The CVE record and NVD detail provide official information about the vulnerability. The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file. Limited source detail is provided, and defenders should verify the vulnerability with official sources and assess their exposure.
Official resources
-
CVE-2026-12968 CVE record
CVE.org
-
CVE-2026-12968 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T07:16:34.710Z and has not been modified since then.