CVE-2026-66480: WordPress YITH WooCommerce Product Add-Ons plugin <= 4.34.0 - Sensitive Data Exposure vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in YITH YITH WooCommerce Product Add-Ons allows Retrieve Embedded Sensitive Data.
This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.34.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YITH WooCommerce Product Add-Onsto a version that resolves this vulnerability.Fixed in 4.34.1
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The reported vector is network-accessible, with low attack complexity. No privileges or user interaction are required.
What security impact is reported?
The issue may allow unauthorized retrieval of embedded sensitive data, affecting confidentiality only. The reported impact is low confidentiality impact, with no integrity or availability impact.
Which plugin versions are affected?
YITH WooCommerce Product Add-Ons versions through 4.34.0 are reported as affected. The available data does not identify a fixed version.