Back to overview

CVE-2026-12968

Description
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.

Metadata

CVE ID
CVE-2026-12968
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-23 09:24 UTC
Published
2026-07-22 06:00 UTC
Last updated
2026-07-22 06:00 UTC
Vendor / Product
Unknown / Product Addons and Product Options With Custom Fields
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Product Addons and Product Options With Custom Fields 0 < 1.6.15
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
Back to overview