PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12968 Product Addons and Product Options With Custom Fields CVE debrief

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 has an unauthenticated file-upload endpoint that accepts SVG files. These files are stored and served inline, allowing an attacker to upload a malicious SVG with an embedded script. This script can execute in the session of any user, such as an administrator, who later opens the file. The vulnerability affects users of the plugin, particularly those with versions before 1.6.15. Administrators and users who may interact with uploaded SVG files are at risk. Limited source detail is provided, and defenders should verify the vulnerability with official sources and assess their exposure.

Vendor
Product Addons and Product Options With Custom Fields
Product
Product Addons and Product Options With Custom Fields WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Users of the Product Addons and Product Options With Custom Fields WordPress plugin, particularly those with versions before 1.6.15, should be aware of this vulnerability. Administrators and users who may interact with uploaded SVG files are at risk. They should review the official CVE record and NVD detail for more information and take necessary defensive measures.

Technical summary

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline. This allows an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file. The vulnerability affects users of the plugin, particularly those with versions before 1.6.15. Administrators and users who may interact with uploaded SVG files are at risk.

Defensive priority

High priority should be given to updating the Product Addons and Product Options With Custom Fields WordPress plugin to version 1.6.15 or later. Additionally, monitoring for suspicious SVG uploads and ensuring proper validation of uploaded files are crucial defensive measures. Review compensating controls for exposed systems while remediation is scheduled and verified.

Recommended defensive actions

  • Update the Product Addons and Product Options With Custom Fields WordPress plugin to version 1.6.15 or later.
  • Monitor for suspicious SVG uploads.
  • Ensure proper validation of uploaded files.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

Evidence for this vulnerability comes from the NVD and a source reference from WPScan. The CVE record and NVD detail provide official information about the vulnerability. The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file. Limited source detail is provided, and defenders should verify the vulnerability with official sources and assess their exposure.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T07:16:34.710Z and has not been modified since then.