Detects WooCommerce Custom Product Addons Pro plugin before version 5.4.2, where the custom pricing formula feature uses PHP eval() on user-submitted values without proper sanitization. Unauthenticated attackers can inject arbitrary PHP code through add-to-cart requests, achieving remote code execution.
Is your app exploitable through CVE-2026-4001?
Scan your domain free