PatchSiren

Product Addons and Product Options With Custom Fields CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Product Addons and Product Options With Custom Fields CVE published 2026-07-22

CVE-2026-12968

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 has an unauthenticated file-upload endpoint that accepts SVG files. These files are stored and served inline, allowing an attacker to upload a malicious SVG with an embedded script. This script can execute in the session of any user, such as an administrator, who later opens the file. The vulnerability affects users o [truncated]