CVE-2026-49061: WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerability
Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPC Product Options for WooCommerce Pluginto a version that resolves this vulnerability.Fixed in 3.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49061?
CVE-2026-49061 has a severity rating of high at 7.5 on the CVSS scale.
What vulnerability does CVE-2026-49061 describe?
CVE-2026-49061 describes an unauthenticated arbitrary file download vulnerability in WPC Product Options for WooCommerce plugin versions 3.2.1 and below.
How do I fix CVE-2026-49061?
To fix CVE-2026-49061, users should update the WPC Product Options for WooCommerce plugin to the latest version beyond 3.2.1.
What impact does CVE-2026-49061 have on my website?
CVE-2026-49061 can allow an attacker to download sensitive files from your website, posing a significant security risk.
Is my site vulnerable if I use an affected version of WPC Product Options for WooCommerce?
Yes, if you are using WPC Product Options for WooCommerce plugin version 3.2.1 or earlier, your site is vulnerable to CVE-2026-49061.