CVE-2026-12968 PUBLISHED

Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload

Assigner: WPScan
Reserved: 23.06.2026 Published: 22.07.2026 Updated: 22.07.2026

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.

Product Status

Vendor Unknown
Product Product Addons and Product Options With Custom Fields
Versions Default: unaffected
  • affected from 0 to 1.6.15 (excl.)

Credits

  • Haitam Lazaar finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE