plugin

Product Input Fields For Woocommerce Vulnerabilities

12 known security issues reported for the Product Input Fields For Woocommerce WordPress plugin. Most recent disclosed Aug 7, 2026.

1 critical 2 high 2 medium

Running Product Input Fields For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Product Input Fields for WooCommerce <= 2.0.1 - Unauthenticated Arbitrary File Upload

critical

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.1. This is due to missing file type validation based on file content, allowing any file type to be stored in the uploads directory without restriction. This makes it possible for un...

CVSS:
9.8
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Aug 7, 2026

CVE-2026-19089 on NVD →

Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.12.2

unknown

[en] The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0. This may make it possible for unauthenticated attackers to uploa...

Affected:
up to 1.12.2
Fixed in:
1.12.2
Disclosed:
Mar 8, 2025

CVE-2024-13359 on NVD →

Product Input Fields for WooCommerce <= 1.12.0 - Unauthenticated Limited File Upload

high

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0. This may make it possible for unauthenticated attackers to upload arb...

CVSS:
8.1
Affected:
up to 1.12.0
Fixed in:
1.12.1
Disclosed:
Mar 7, 2025

CVE-2024-13359 on NVD →

Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 2.0

unknown

[en] The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access a...

Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
Nov 26, 2024

CVE-2024-10857 on NVD →

Product Input Fields for WooCommerce <= 1.9 - Authenticated (Contributor+) Arbitrary File Read

medium

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and ab...

CVSS:
6.5
Affected:
up to 1.9
Fixed in:
2.0
Disclosed:
Nov 25, 2024

CVE-2024-10857 on NVD →

Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.8.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Product Input Fields for WooCommerce.This issue affects Product Input Fields for WooCommerce: from n/a through 1.7.0.

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Apr 15, 2024

CVE-2024-31431 on NVD →

Product Input Fields for WooCommerce <= 1.7.0 - Cross-Site Request Forgery to Notice Dismissal

medium

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation on the dismiss_notice() function. This makes it possible for unauthenticated attackers to dismiss notices via a forged r...

CVSS:
4.3
Affected:
up to 1.7.0
Fixed in:
1.8.0
Disclosed:
Apr 10, 2024

CVE-2024-31431 on NVD →

Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.2.7

unknown

[en] The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Jun 7, 2023

CVE-2020-36696 on NVD →

Product Input Fields for WooCommerce <= 1.2.6 - Missing Authorization

high

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.

CVSS:
7.5
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Aug 3, 2020

CVE-2020-36696 on NVD →

Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.2.7

unknown

Unauthenticated Arbitrary File Download vulnerability discovered by NinTechNet in WordPress Product Input Fields for WooCommerce plugin (versions <= 1.2.6).

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Aug 3, 2020

Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.2.7

unknown

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Aug 3, 2020

Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.2.7

unknown

The lack of authorisation checks in the handle_downloads() function, hooked to admin_init() could allow unauthenticated users to download arbitrary files from the blog using a path traversal payload.

Affected:
up to 1.2.7
Fixed in:
1.2.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database