PHP Object Injection in Advanced Product Fields for WooCommerce
CVE-2026-39499
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 June 2026
What is CVE-2026-39499?
A vulnerability has been identified in the Advanced Product Fields (Product Addons) for WooCommerce where the Shop Manager role can exploit PHP Object Injection. This flaw affects versions up to 1.6.19, allowing unauthorized actions that can compromise the integrity and security of the application.
Affected Version(s)
Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19