No analysis available yet.
Vendor Solution
Update the WordPress Advanced Product Fields (Product Addons) for WooCommerce Plugin to the latest available version (at least 1.6.20).
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 16 Jun 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wombat Plugins
Wombat Plugins advanced Product Fields Product Addons For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Wombat Plugins
Wombat Plugins advanced Product Fields Product Addons For Woocommerce Wordpress Wordpress wordpress |
Mon, 15 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | |
| Title | WordPress Advanced Product Fields (Product Addons) for WooCommerce plugin <= 1.6.19 - PHP Object Injection vulnerability | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-06-15T20:17:54.975Z
Reserved: 2026-04-07T10:47:43.843Z
Link: CVE-2026-39499
No data.
Status : Deferred
Published: 2026-06-15T21:16:45.230
Modified: 2026-06-15T21:24:32.790
Link: CVE-2026-39499
No data.
OpenCVE Enrichment
Updated: 2026-06-16T04:15:02Z
-
CWE-502
Deserialization of Untrusted Data