Review
Product Addons and Product Options With Custom Fields
CVE published 2026-07-22
CVE-2026-12968
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 has an unauthenticated file-upload endpoint that accepts SVG files. These files are stored and served inline, allowing an attacker to upload a malicious SVG with an embedded script. This script can execute in the session of any user, such as an administrator, who later opens the file. The vulnerability affects users o [truncated]