Input validation vulnerability in Product Addons for Woocommerce – Product Options with Custom Fields 3.1.0

A plugin for WordPress called “Product Addons for Woocommerce – Product Options with Custom Fields” has a security issue in all versions up to 3.1.0. This is because it doesn’t properly check the information entered in the ‘operator’ field when using conditional logic. This means that someone with manager-level access or higher could inject and run any PHP code they want on the server by manipulating the ‘operator’ field when saving addon form field rules.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.