CVE-2026-12968
Product Addons โ WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.
| Vendor | unknown |
| Product | product addons and product options with custom fields |
| Published | Jul 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown product addons and product options with custom fields
Be the first to know when new unknown vulnerabilities affecting unknown product addons and product options with custom fields are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Product Addons and Product Options With Custom Fields
0 < 1.6.15
References
Credits
Haitam Lazaar WPScan