Description
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
Published: 2026-09-30
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw is a PHP Object Injection vulnerability found in the WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin up to version 3.3.8. By manipulating serialized data submitted through the plugin’s input fields, an attacker can force PHP to deserialize crafted objects, allowing the injection of arbitrary code. Successful exploitation could give the attacker full control over the hosting environment, compromising confidentiality, integrity, and availability of the WordPress site and potentially the underlying server. The weakness is identified as CWE-502.

Affected Systems

ThemeHigh’s Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin versions 3.3.8 and earlier are affected.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity vulnerability. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. While explicit prerequisites are not detailed in the advisory, the likely attack path would involve sending a malicious payload through the plugin’s form interface, which requires authenticated access to the WordPress admin area. If the plugin exposes endpoints to unauthenticated users, the risk increases further, but the documented exploitation vector appears to be through administrative input processing.

Generated by OpenCVE AI on September 30, 2026 at 19:16 UTC.

Remediation

Vendor Solution

Update the WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin to the latest available version (at least 3.3.9).


OpenCVE Recommended Actions

  • Update the WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin to version 3.3.9 or later.
  • If updating is not immediately possible, deactivate or uninstall the plugin to eliminate the attack surface.
  • Apply web‑application firewall or input‑validation rules to block serialized object payloads before they reach the plugin’s processing logic.

Generated by OpenCVE AI on September 30, 2026 at 19:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
Title WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin <= 3.3.8 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T17:59:54.701Z

Reserved: 2026-09-29T00:15:56.342Z

Link: CVE-2026-102392

cve-icon Vulnrichment

Updated: 2026-09-30T17:59:11.994Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:18:14.713

Modified: 2026-09-30T19:04:41.917

Link: CVE-2026-102392

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:30:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data