A plugin called Product Addons & Fields for WooCommerce on WordPress has a security issue that allows attackers to upload any type of file to a website using the plugin. This could potentially allow them to gain control of the site. The vulnerability exists in all versions up to 32.0.18. To exploit it, the PPOM Pro plugin and a WooCommerce product with a file upload field must be present.