OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102392

HIGH · CVSS 7.2 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects the Extra Product Options for WooCommerce and Custom Product Addons and Fields plugins, specifically in versions up to 3.3.8, allowing for PHP Object Injection. This could lead to remote code execution, enabling attackers to execute arbitrary PHP code on the server. E-commerce businesses using these plugins should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-102392
Severity
HIGH
CVSS
7.2
EPSS
0.30%

Original NVD Description

Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.