CVE-2026-102392: WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin <= 3.3.8 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
Affected Software
1 affected component
ThemeHigh Extra Product Options For WooCommerce | Custom Product Addons and Fields<=3.3.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fieldsto a version that resolves this vulnerability.Fixed in 3.3.9
Event History
Sep 30, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which accounts could exploit this issue?
The issue is associated with the Shop manager role. The CVSS vector indicates that high privileges are required, with no user interaction required.
2
Which installations should be reviewed?
Review installations of ThemeHigh Extra Product Options For WooCommerce | Custom Product Addons and Fields running version 3.3.8 or earlier.
3
What is the potential security impact?
The published CVSS score is 7.2 (High), with high impacts listed for confidentiality, integrity, and availability.