All verified exploits

CVE-2026-4001 WooCommerce Custom Product Addons Pro RCE

Deterministic critical WordPress Added cve-verified-cve-2026-4001

Detects WooCommerce Custom Product Addons Pro plugin before version 5.4.2, where the custom pricing formula feature uses PHP eval() on user-submitted values without proper sanitization. Unauthenticated attackers can inject arbitrary PHP code through add-to-cart requests, achieving remote code execution.

Related WordPress exploits

Is your app exploitable through CVE-2026-4001?

Scan your domain free