CVE-2026-2296 | Product Addons for Woocommerce Plugin up to 3.1.0 on WordPress evalConditions operator code injection
A vulnerability was found in Product Addons for Woocommerce Plugin up to 3.1.0 on WordPress. It has been declared as critical. Affected by this issue is the function evalConditions. The manipulation of the argument operator results in code injection.
This vulnerability is known as CVE-2026-2296. It is possible to launch the attack remotely. No exploit is available.