CVE-2026-4001Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within includes/process/price.php. This is due to insufficient sanitization and validation of user-submitted field values before passing them to PHP's eval() function. The sanitize_values() method strips HTML tags but does not escape single quotes or prevent PHP code injection. This makes it possible for unauthenticated attackers to execute arbitrary code on the server by submitting a crafted value to a WCPA text field configured with custom pricing formula (pricingType: "custom" with {this.value}).

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-03-24); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01345Mentions · 2026-03-23: 1Mentions · 2026-03-24: 5Mentions · 2026-03-25: 1Mentions · 2026-04-08: 1Mentions · 2026-06-05: 1PoC Mentioned / Linked · 2026-03-23: 1Active Exploitation · 2026-06-05: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-06-05: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 5Technical Details · 2026-03-25: 1Technical Details · 2026-04-08: 1Technical Details · 2026-06-05: 103-2303-2403-2504-0806-05
Signal classification4 categories
Disclosure
555.6%
Patch
222.2%
General
111.1%
Active Exploitation
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-231
Disclosure1
2026-03-245
Disclosure4Patch1
2026-03-251
General1
2026-04-081
Patch1
2026-06-051
Active Exploitation1
Full discourse9 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4001 — CVSS 9.8/10 ██████████ The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions... Severity: CRITICAL Patch now. #cybersecurity #CVE

    Post summary

    The post announces a critical Remote Code Execution vulnerability in the Woocommerce Custom Product Addons Pro plugin and urges users to apply the available patch.

    1001041
    9 followersView on X
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-4001 — CVSS 9.8/10 ██████████ The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/wCJvLyaG66

    Post summary

    The tweet announces a critical RCE vulnerability (CVE-2026-4001) in WooCommerce's Custom Product Addons Pro plugin and urges users to apply a patch.

    1000037
    9 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4001: Woocommerce ... Raw eval() on user input with only HTML stripping - classic PHP footgun that turns every product page into a backdoor. #RCE #WordPress #eval. https://zerodaysignal.com/vulnerability/CVE-2026-4001 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-4001, noting that unchecked eval() usage can lead to remote code execution on WooCommerce product pages, and links to a resource that presumably includes a PoC, but provides no exploit code, patch information, or evidence of active exploitation.

    0000162
    165 followersView on X
  • Wordfence@wordfence
    Active Exploitation

    Active RCE Exploitation in WooCommerce Add-ons Wordfence Security News Clip | May 25, 2026 Attackers are actively targeting CVE-2026-4001, an unauthenticated RCE flaw in WooCommerce Custom Product Add-ons Pro affecting an estimated 21,000 installations. The plugin passes user-controlled pricing formula values directly into PHP's eval function without sufficient sanitization, enabling arbitrary code execution via a crafted add-to-cart request. Update WooCommerce Custom Product Add-ons Pro to version 5.4.2 immediately. Watch The Clip For More Details: https://youtube.com/shorts/lBCYMu3nRiA

    Post summary

    Attackers are exploiting an unauthenticated RCE in WooCommerce Custom Product Add-ons Pro; an immediate update to version 5.4.2 is required.

    00000116
    8.2K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    #WordPress security alert: CVE-2026-4001 A critical #RCE flaw in WooCommerce Custom Product Addons Pro ≤ 5.4.1. https://www.cve.org/CVERecord?id=CVE-2026-4001 Attackers may exploit custom pricing formulas without authentication and potentially take over the server. Update to 5.4.2 fast and scan for compromise 👉 https://quttera.com/wordpress-malware-scanner #WooCommerce #WordPressSecurity #CVE #Malware #SilentRisk

    Post summary

    The post alerts of a critical RCE in WooCommerce Custom Product Addons Pro up to 5.4.1 and urges users to upgrade to 5.4.2 and run a malware scan, but does not confirm active exploitation or provide a PoC.

    0000055
    38 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4001 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4001 #CVE-2026-4001 #CVE #Critical #Wordpress #CyberSecurity #InfoSec https://t.co/UZUl8eAGL8

    Post summary

    A tweet announces the new CVE‑2026‑4001, noting severity 9.8 and that it affects WordPress, provides a link to the NVD entry, but offers no exploit, patch, or active‑exploitation details.

    0000044
    114 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4001 The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing… https://www.cve.org/CVERecord?id=CVE-2026-4001

    Post summary

    The post announces CVE‑2026‑4001, describing a Remote Code Execution vulnerability in the Woocommerce Custom Product Addons Pro plugin up to version 5.4.1, but does not provide a PoC, exploit, or patch information.

    00000172
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4001: CRITICAL] Woocommerce Custom Product Addons Pro plugin for WordPress up to v5.4.1 is vulnerable to Remote Code Execution due to insufficient user input validation, allowing attackers to execute...#cve,CVE-2026-4001,#cybersecurity https://cvefind.com/CVE-2026-4001

    Post summary

    An announcement of a critical RCE flaw in the Woocommerce Custom Product Addons Pro plugin (v5.4.1 or earlier) caused by insufficient input validation.

    0000051
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4001 - Critical The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in t... https://www.thehackerwire.com/vulnerability/CVE-2026-4001/ https://t.co/drZf6qiXxo

    Post summary

    The post announces a critical RCE vulnerability in the Woocommerce Custom Product Addons Pro plugin, affecting all versions up to 5.4.1 via eval() in the custom pricing formula; no exploit, patch, or PoC is provided.

    0000037
    145 followersView on X

Explore more