Remote Code Execution Vulnerability in Woocommerce Custom Product Addons Pro by WordPress
CVE-2026-4001
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 March 2026
What is CVE-2026-4001?
The Woocommerce Custom Product Addons Pro plugin for WordPress has a vulnerability that allows Remote Code Execution due to insufficient sanitization of user inputs. Specifically, in the process_custom_formula() function, user-defined custom pricing formulas are not properly validated before being processed by PHP's eval() function. As a result, unauthenticated attackers can exploit this flaw by submitting malicious inputs to achieve arbitrary code execution on the server.
Affected Version(s)
Woocommerce Custom Product Addons Pro 0 <= 5.4.1