Woocommerce Custom Product Addons Pro - Unauthenticated Remote Code Execution via Custom Pricing Formula vulnerability
critical
Unauthenticated Remote Code Execution via Custom Pricing Formula vulnerability
- CVSS:
- 10
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.2
- Disclosed:
- Mar 24, 2026
Woocommerce Custom Product Addons Pro <= 5.4.1 - Unauthenticated Remote Code Execution via Custom Pricing Formula
critical
The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within includes/process/price.php. This is due to insufficient sanitization and validation of u...
- CVSS:
- 9.8
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.2
- Disclosed:
- Mar 23, 2026
CVE-2026-4001 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database