Orizon[verified]@OrizonCyberPatch
The post announces a critical Remote Code Execution vulnerability in the Woocommerce Custom Product Addons Pro plugin and urges users to apply the available patch.
Orizon[verified]@OrizonCyberDisclosure
The tweet announces a critical RCE vulnerability (CVE-2026-4001) in WooCommerce's Custom Product Addons Pro plugin and urges users to apply a patch.
Wordfence[verified]@wordfenceActive Exploitation
Attackers are exploiting an unauthenticated RCE in WooCommerce Custom Product Add-ons Pro; an immediate update to version 5.4.2 is required.
Quttera - eCommerce Security[verified]@MNovofastovskyPatch
The post alerts of a critical RCE in WooCommerce Custom Product Addons Pro up to 5.4.1 and urges users to upgrade to 5.4.2 and run a malware scan, but does not confirm active exploitation or provide a PoC.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE-2026-4001, noting that unchecked eval() usage can lead to remote code execution on WooCommerce product pages, and links to a resource that presumably includes a PoC, but provides no exploit code, patch information, or evidence of active exploitation.
CVEarity@CVEarityGeneral
A tweet announces the new CVE‑2026‑4001, noting severity 9.8 and that it affects WordPress, provides a link to the NVD entry, but offers no exploit, patch, or active‑exploitation details.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑4001, describing a Remote Code Execution vulnerability in the Woocommerce Custom Product Addons Pro plugin up to version 5.4.1, but does not provide a PoC, exploit, or patch information.
CVEFind.com@CveFindComDisclosure
An announcement of a critical RCE flaw in the Woocommerce Custom Product Addons Pro plugin (v5.4.1 or earlier) caused by insufficient input validation.