CVE-2026-4001 | acowebs Woocommerce Custom Product Addons Pro Plugin up to 5.4.1 on WordPress price.php eval Field eval injection (EUVD-2026-14652)
A vulnerability was found in acowebs Woocommerce Custom Product Addons Pro Plugin up to 5.4.1 on WordPress. It has been classified as critical. Affected is the function eval of the file includes/process/price.php. The manipulation of the argument Field leads to improper neutralization of directives in dynamically evaluated code.
This vulnerability is uniquely identified as CVE-2026-4001. The attack is possible to be carried out remotely. No exploit exists.