Impact
The vulnerability is a stored cross‑site scripting flaw in the Product Addons and Product Options With Custom Fields WordPress plugin. An unauthenticated attacker can upload a SVG file because the plugin does not restrict the file‑upload endpoint. The SVG is stored and served inline, so any embedded script in the SVG will execute in the browser session of a user who later opens it.
Affected Systems
The affected product is the WordPress plugin Product Addons and Product Options With Custom Fields at any version before 1.6.15. Specific vendor information is not disclosed in the CVE record.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity flaw. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation probability but still a significant risk. Exploitation requires no authentication; the attacker simply uploads a malicious SVG through the open upload endpoint, after which any user who views the file is impacted.
OpenCVE Enrichment