Description
WordPress Plugin Product Addons & Fields for WooCommerce is prone to same origin method execution (SOME) vulnerability. The impact of a SOME attack is similar to the impact of cross-site scripting, though there are some important and distinguishing exploitation restrictions. An attacker may leverage this issue to hijack dangerous web functionality and even exfiltrate sensitive user data. WordPress Plugin Product Addons & Fields for WooCommerce version 14.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 14.1 or latest
References
https://gist.github.com/cure53/09a81530a44f6b8173f545accc9ed07e
https://plugins.svn.wordpress.org/woocommerce-product-addon/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Scripting (1.9.1)
WordPress Plugin Autoptimize Multiple Vulnerabilities (2.7.6)
WordPress Plugin Events Widgets For Elementor And The Events Calendar Security Bypass (1.4.3)
WordPress Plugin Download Manager Cross-Site Scripting (3.2.52)