CVE-2026-12968

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.
Configurations

No configuration.

History

22 Jul 2026, 14:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-79

22 Jul 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-22 07:16

Updated : 2026-07-22 16:30


NVD link : CVE-2026-12968

Mitre link : CVE-2026-12968

CVE.ORG link : CVE-2026-12968


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')