PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12968 Product Addons and Product Options With Custom Fields CVE debrief

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 has an unauthenticated file-upload endpoint that accepts SVG files. These files are stored and served inline, allowing an attacker to upload a malicious SVG with an embedded script. This script can execute in the session of any user, such as an administrator, who later opens the file. The vulnerability affects users of the plugin, particularly those with versions before 1.6.15. Administrators and users who may interact with uploaded SVG files are at risk. Limited source detail is provided, and defenders should verify the vulnerability with official sources and assess their exposure.

Vendor
Product Addons and Product Options With Custom Fields
Product
Product Addons and Product Options With Custom Fields WordPress plugin
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Users of the Product Addons and Product Options With Custom Fields WordPress plugin, particularly those with versions before 1.6.15, should be aware of this vulnerability. Administrators and users who may interact with uploaded SVG files are at risk. They should review the official CVE record and NVD detail for more information and take necessary defensive measures.

Technical summary

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline. This allows an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file. The vulnerability affects users of the plugin, particularly those with versions before 1.6.15. Administrators and users who may interact with uploaded SVG files are at risk.

Defensive priority

High priority should be given to updating the Product Addons and Product Options With Custom Fields WordPress plugin to version 1.6.15 or later. Additionally, monitoring for suspicious SVG uploads and ensuring proper validation of uploaded files are crucial defensive measures. Review compensating controls for exposed systems while remediation is scheduled and verified.

Recommended defensive actions

  • Update the Product Addons and Product Options With Custom Fields WordPress plugin to version 1.6.15 or later.
  • Monitor for suspicious SVG uploads.
  • Ensure proper validation of uploaded files.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

Evidence for this vulnerability comes from the NVD and a source reference from WPScan. The CVE record and NVD detail provide official information about the vulnerability. The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file. Limited source detail is provided, and defenders should verify the vulnerability with official sources and assess their exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12968 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12968

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12968 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12968

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.