Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
The CVSS severity warrants an early asset and exposure review.CVE-2026-39498 affects Yeeaddons YayMail. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-39493 affects NSquared Simply Schedule Appointments. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-39492 affects Flipper Code – WordPress Development Company WP Maps. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-39481 affects WP Chill Modula Image Gallery. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-39480 affects Inisev Backup Migration. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
The CVSS severity warrants an early asset and exposure review.CVE-2026-39474 affects metaphorcreations Post Duplicator. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
The CVSS severity warrants an early asset and exposure review.CVE-2026-39471 affects ShortPixel ShortPixel Image Optimizer. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.
The CVSS severity warrants an early asset and exposure review.Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
The CVSS severity warrants an early asset and exposure review.CVE-2026-39463 affects ManageWP ManageWP Worker. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-39450 affects Aman FunnelKit Automations. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.
The CVSS severity warrants an early asset and exposure review.