plugin

Woo Custom Product Addons Vulnerabilities

1 known security issue reported for the Woo Custom Product Addons WordPress plugin. Most recent disclosed Feb 17, 2026.

1 high

Running Woo Custom Product Addons on your site? Check whether your installed version is affected.

Scan your site free

Product Addons for Woocommerce – Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter

high

The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 3.1.0. This is due to insufficient input validation of the 'operator' field in conditional logic rules within the evalConditions() function, which passes uns...

CVSS:
7.2
Affected:
up to 3.1.0
Fixed in:
3.1.1
Disclosed:
Feb 17, 2026

CVE-2026-2296 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database