๐Ÿ” CVE Alert

CVE-2026-12968

UNKNOWN 0.0

Product Addons โ€“ WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.

Vendor unknown
Product product addons and product options with custom fields
Published Jul 22, 2026
Stay Ahead of the Next One

Get instant alerts for unknown product addons and product options with custom fields

Be the first to know when new unknown vulnerabilities affecting unknown product addons and product options with custom fields are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Product Addons and Product Options With Custom Fields
0 < 1.6.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/8ae2ff84-a4a0-4fb1-842b-b3193e673d27/

Credits

Haitam Lazaar WPScan