Title: Security issue
Last modified: March 8, 2025

---

# Security issue

 *  Resolved [groggy72](https://wordpress.org/support/users/groggy72/)
 * (@groggy72)
 * [1 year, 3 months ago](https://wordpress.org/support/topic/security-issue-172/)
 *  1.12.1 has a major security issue
 * [https://patchstack.com/database/wordpress/plugin/product-input-fields-for-woocommerce/vulnerability/wordpress-product-input-fields-for-woocommerce-plugin-1-12-1-unauthenticated-limited-file-upload-vulnerability?_a_id=350](https://patchstack.com/database/wordpress/plugin/product-input-fields-for-woocommerce/vulnerability/wordpress-product-input-fields-for-woocommerce-plugin-1-12-1-unauthenticated-limited-file-upload-vulnerability?_a_id=350)

Viewing 4 replies - 1 through 4 (of 4 total)

 *  Plugin Support [oluisrael](https://wordpress.org/support/users/oluisrael/)
 * (@oluisrael)
 * [1 year, 3 months ago](https://wordpress.org/support/topic/security-issue-172/#post-18350577)
 * [@groggy72](https://wordpress.org/support/users/groggy72/) thank you for bringing
   this to our attention. We’re already working on patching the vulnerability. An
   update will be rolled out as soon as the security issue is patched.
 * Thank you
 *  Plugin Support [oluisrael](https://wordpress.org/support/users/oluisrael/)
 * (@oluisrael)
 * [1 year, 2 months ago](https://wordpress.org/support/topic/security-issue-172/#post-18362516)
 * Thank you for your patience regarding the recent security advisory related to
   our plugin. We sincerely apologize for any confusion or concern caused by inaccuracies
   in the information initially reported.
   Upon further review, we discovered that
   this issue resulted from an error in the wrong affected version range and patched
   version input and details from the CNA responsible for filing the CVE record.
   This caused other vulnerability databases to pick up on the error and CVE entry.
   Their records and the associated CVE entry have now been corrected. A clarifying
   note has also been added to the advisory to reflect this update.Key details:1.
   The patched version of the plugin (already released and available) resolves the
   issue. It is v1.12.1, and I can confirm that it is safe to run on websites.2.
   The corrected advisory now accurately reflects the affected versions, ensuring
   transparency.Rest assured, your site’s security remains our top priority. If 
   you’ve updated to the latest version (v1.12.1) of the plugin, no further action
   is needed. If you have questions or require assistance, please reply to this 
   thread.Thank you for your understanding._P.S. Stay updated by following our plugin’s
   changelog or subscribing to our security notifications_
 *  Thread Starter [groggy72](https://wordpress.org/support/users/groggy72/)
 * (@groggy72)
 * [1 year, 2 months ago](https://wordpress.org/support/topic/security-issue-172/#post-18362596)
 * Many thanks for clarifying
 *  Plugin Support [oluisrael](https://wordpress.org/support/users/oluisrael/)
 * (@oluisrael)
 * [1 year, 2 months ago](https://wordpress.org/support/topic/security-issue-172/#post-18363573)
 * You’re welcome, [@groggy72](https://wordpress.org/support/users/groggy72/)

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Security issue’ is closed to new replies.

 * ![](https://ps.w.org/product-input-fields-for-woocommerce/assets/icon-256x256.
   png?rev=2717446)
 * [Product Input Fields for WooCommerce](https://wordpress.org/plugins/product-input-fields-for-woocommerce/)
 * [Support Threads](https://wordpress.org/support/plugin/product-input-fields-for-woocommerce/)
 * [Active Topics](https://wordpress.org/support/plugin/product-input-fields-for-woocommerce/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/product-input-fields-for-woocommerce/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/product-input-fields-for-woocommerce/reviews/)

 * 8 replies
 * 2 participants
 * Last reply from: [oluisrael](https://wordpress.org/support/users/oluisrael/)
 * Last activity: [1 year, 2 months ago](https://wordpress.org/support/topic/security-issue-172/#post-18363573)
 * Status: resolved