plugin

Additional Product Fields For Woocommerce Vulnerabilities

6 known security issues reported for the Additional Product Fields For Woocommerce WordPress plugin. Most recent disclosed Aug 20, 2026.

4 medium

Running Additional Product Fields For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Extra Product Options Builder for WooCommerce < 1.2.176 - Missing Authorization

medium

The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.2.176. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.176
Fixed in:
1.2.176
Disclosed:
Aug 20, 2026

CVE-2026-19728 on NVD →

Extra Product Options Builder for WooCommerce <= 1.2.167 - Missing Authorization

medium

The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.167. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.167
Fixed in:
1.2.168
Disclosed:
Jul 8, 2026

CVE-2026-57390 on NVD →

Extra Product Options Builder for WooCommerce [additional-product-fields-for-woocommerce] < 1.2.134

unknown

[en] The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'RednaoSerializedFields' parameter during the creation of a signature file in all versions up to, and including, 1.2.133 due to insufficient input sanitization and output escaping. This makes...

Affected:
up to 1.2.134
Fixed in:
1.2.134
Disclosed:
Oct 24, 2024

CVE-2024-9214 on NVD →

Extra Product Options Builder for WooCommerce <= 1.2.133 - Unauthenticated Stored Cross-Site Scripting

medium

The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'RednaoSerializedFields' parameter during the creation of a signature file in all versions up to, and including, 1.2.133 due to insufficient input sanitization and output escaping. This makes it p...

CVSS:
6.1
Affected:
up to 1.2.133
Fixed in:
1.2.134
Disclosed:
Oct 23, 2024

CVE-2024-9214 on NVD →

Extra Product Options Builder for WooCommerce [additional-product-fields-for-woocommerce] < 1.2.105

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in RedNao Extra Product Options Builder for WooCommerce.This issue affects Extra Product Options Builder for WooCommerce: from n/a through 1.2.104.

Affected:
up to 1.2.105
Fixed in:
1.2.105
Disclosed:
Apr 15, 2024

CVE-2024-31940 on NVD →

Extra Product Options Builder for WooCommerce <= 1.2.104 - Cross-Site Request Forgery to Notice Dismissal

medium

The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.104. This is due to missing or incorrect nonce validation on the DontShowAgain() function. This makes it possible for unauthenticated attackers to dismiss notices via...

CVSS:
4.3
Affected:
up to 1.2.104
Fixed in:
1.2.105
Disclosed:
Apr 10, 2024

CVE-2024-31940 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database