CVE-2026-39499: PHP Object Injection in Advanced Product Fields for WooCommerce ≤1.6.19
A PHP object injection vulnerability exists in the Advanced Product Fields (Product Addons) plugin for WooCommerce versions 1.6.19 and earlier. Shop managers—authenticated users with elevated privileges—can inject malicious PHP objects that execute arbitrary code on the server. The vulnerability requires an authenticated attacker with shop manager or higher role, so it does not pose an immediate risk to unauthenticated visitors, but it represents a significant lateral-movement or privilege-escalation vector for compromised or malicious insiders.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-502
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-15 / 2026-06-17
NVD description (verbatim)
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-39499 is a PHP object injection vulnerability (CWE-502: Deserialization of Untrusted Data) in Advanced Product Fields for WooCommerce up to version 1.6.19. The plugin fails to properly validate or sanitize serialized PHP objects before unserializing them, allowing an authenticated shop manager to craft and inject malicious object chains that achieve remote code execution. The attack vector is network-based with no user interaction required beyond the attacker's own authenticated action, and it bypasses standard access controls by leveraging the built-in capabilities of the shop manager role.
Business impact
Successful exploitation allows a malicious or compromised shop manager to execute arbitrary PHP code within the WooCommerce environment, leading to full compromise of the e-commerce installation. An attacker could exfiltrate customer data, payment information, or intellectual property; modify product listings and pricing; inject malware into the storefront; or pivot laterally to underlying systems. For multi-tenant or SaaS deployments, this could affect multiple merchants. The high CVSS score (7.2) reflects the severity: while authentication is required, the impact spans confidentiality, integrity, and availability.
Affected systems
Advanced Product Fields (Product Addons) plugin for WooCommerce versions 1.6.19 and earlier are vulnerable. The attack requires the WooCommerce platform and PHP environment to be in use. Any site running an affected version with shop manager accounts is at risk, particularly if those accounts are shared, delegated to contractors, or otherwise exposed to compromise.
Exploitability
Exploitation requires valid shop manager or administrator credentials and network access to the WordPress admin panel or vulnerable API endpoints. The attack complexity is low—no special conditions, race conditions, or user interaction are needed once the attacker is authenticated. There are no public exploits documented in CISA KEV as of the analysis date, but the vulnerability is straightforward to exploit once the injection point is identified. Internal threats or compromised credentials pose the highest immediate risk.
Remediation
Update Advanced Product Fields (Product Addons) to a patched version released after 1.6.19. Verify the exact version number in the vendor advisory or plugin repository. As an interim control, restrict shop manager role assignments to trusted personnel only, enforce strong authentication (including multi-factor authentication), monitor admin panel access logs, and consider disabling the plugin if it is not actively used. Review user accounts with shop manager privileges and audit their recent activity.
Patch guidance
Obtain the latest version of Advanced Product Fields (Product Addons) directly from the WordPress plugin repository or the vendor's official website. Verify that the version number is higher than 1.6.19 before deployment. Test the update in a staging environment to confirm compatibility with your WooCommerce and PHP versions. Deploy during a maintenance window and verify functionality of product addon features post-update. If auto-updates are enabled, ensure they are configured to apply security patches promptly.
Detection guidance
Monitor PHP error logs and application logs for unserialize() warnings or exceptions related to the product addons plugin. Search web server access logs for unusual POST requests to admin endpoints or REST API endpoints used by the plugin. Audit WordPress user activity logs (via security plugins such as Wordfence or Sucuri) for shop manager account logins from unexpected locations or times, or rapid API calls suggestive of exploitation. Check file integrity of the plugin directory for unauthorized modifications. Network-based detection should focus on anomalous outbound connections from the web server immediately following admin panel access.
Why prioritize this
This vulnerability merits urgent patching because it combines high severity (CVSS 7.2), full confidentiality/integrity/availability impact, and a common WordPress environment. Although it requires authentication, the shop manager role is often delegated and may be compromised through credential theft, phishing, or insider threats. E-commerce sites storing payment or customer data face regulatory and reputational risk. Delaying the patch extends the window in which a compromised account could lead to data breach or operational disruption.
Risk score, explained
CVSS 3.1 score of 7.2 (HIGH) is driven by: (1) Network attack vector—the vulnerability is reachable via the network; (2) Low attack complexity—no special conditions required beyond valid credentials; (3) High privilege requirement—shop manager role is needed, which is a control that mitigates unauthenticated attacks; (4) High impact across confidentiality, integrity, and availability—unserialize() allows arbitrary code execution. The score does not account for threat landscape or likelihood of credential compromise, which would further elevate risk in practice.
Frequently asked questions
Do I need to update if my WooCommerce site does not use the Advanced Product Fields plugin?
No. This vulnerability is specific to Advanced Product Fields (Product Addons) for WooCommerce. If your site does not use this plugin, you are not affected by CVE-2026-39499. Verify your installed plugins via the WordPress admin panel (Plugins > Installed Plugins).
Can this vulnerability be exploited by unauthenticated users or customers?
No. Exploitation requires valid shop manager or administrator credentials. Unauthenticated visitors and customers cannot trigger the vulnerability. However, if your shop manager account credentials are compromised—via weak passwords, phishing, or credential stuffing—an attacker could exploit this flaw.
What should I do if I suspect my site has been compromised?
Immediately reset all shop manager and administrator passwords, change API keys, and audit recent user logins for suspicious activity. Scan your site and server for malware or backdoors using security tools (Wordfence, Sucuri, or a professional incident response service). Notify your hosting provider and consider a security audit. Do not wait to deploy the patch if compromise is suspected.
Does this affect WooCommerce itself, or only the third-party plugin?
This vulnerability is in the third-party Advanced Product Fields (Product Addons) plugin, not in WooCommerce core. WooCommerce versions are not directly affected. However, any WooCommerce installation with the vulnerable plugin installed is at risk.
This analysis is provided for informational purposes and does not constitute legal or professional security advice. The vulnerability details, CVSS score, and affected versions are derived from official sources as of the publication date (2026-06-15). Patch version numbers and specific remediation steps should be verified against the vendor's official advisory. No warranty is made regarding the accuracy or completeness of this intelligence; organizations should conduct their own risk assessments and testing. Consult with your security team or a qualified cybersecurity professional before making infrastructure changes. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2025-11993HIGHWooCommerce Infinite Scroll Plugin PHP Object Injection – HIGH Severity
- CVE-2026-12191HIGHOpenpilot 0.11 Unsafe Pickle Deserialization – LOCAL RCE
- CVE-2026-20251HIGHSplunk Remote Code Execution via KV Store Deserialization
- CVE-2026-24221HIGHNVIDIA NVTabular Deserialization Vulnerability – Patch & Detection Guide
- CVE-2026-24228HIGHNVIDIA NeMo Deserialization Code Execution Vulnerability
- CVE-2026-24237HIGHNVIDIA NVTabular Deserialization Remote Code Execution Vulnerability
- CVE-2026-25551HIGHBarTender 2021–12.0.1 Insecure Deserialization Privilege Escalation
- CVE-2026-27333HIGHUnauthenticated RCE in Paid Videochat Turnkey Site