LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-12968

Published
CVSS8.8
Severityhigh
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-12968

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-12968.