Executive brief
WowAddons, a WordPress plugin used to add custom product options to e-commerce sites, contains a security flaw that allows attackers to inject malicious scripts. If a site administrator or visitor clicks on a specially crafted link, the attacker can execute code in their browser, potentially leading to unauthorized actions or the theft of sensitive session information. This vulnerability could be used to deface the website or redirect users to malicious locations.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the WPXPO WowAddons (also known as Product Addons) plugin for WordPress due to insufficient input sanitization and output escaping. The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts into pages that are executed in the context of a victim's browser. Exploitation requires user interaction, such as a victim clicking a malicious link. The vulnerability is classified as CWE-79 and has been addressed in version 1.6.15.
Affected products
- WPXPO WowAddons (Product Addons) <= 1.6.14
Timeline
- 2026-03-09: disclosed: Reported by Nguyen Ba Khanh
- 2026-06-30: advisory: Patchstack advisory published
- 2026-07-02: advisory: NVD published CVE-2026-57686
- 2026-07-02: patched: Version 1.6.15 released to address the issue