
WooCommerce Custom Product Addons Pro CVE-2026-4001: Patch Guide
Patch WooCommerce Custom Product Addons Pro CVE-2026-4001, verify product options, review WooCommerce orders, and inspect the site after a critical plugin update.
US-Based WordPress Guidance Provided by Real Tech Experts, NOT Sales Agents
We currently offer only U.S. Based Phone Support in English. Help4WordPress.com
We provide guidance for the Unsupported WordPress Site that all of the other providers won’t. Learn with us.
Fix I.T. Phill offers Do It Yourself WordPress guides or Help4 WordPress does what we call Fully Managed WordPress that includes Development help with we do it for you service.
We don’t do Sales People. Help4 WordPress handles all of the WordPress Backend for you. That includes when a plugin gets out of line and the developer of it needs to be contacted. We do it for you in our Fully Managed Packages.
We currently offer only U.S. Based Phone Support in English. Help4WordPress.com
We provide guidance for the Unsupported WordPress Site that all of the other providers won’t. Learn with us.
Fix I.T. Phill offers Do It Yourself WordPress guides or Help4 WordPress does what we call Fully Managed WordPress that includes Development help with we do it for you service.
We don’t do Sales People. Help4 WordPress handles all of the WordPress Backend for you. That includes when a plugin gets out of line and the developer of it needs to be contacted. We do it for you in our Fully Managed Packages.

Patch WooCommerce Custom Product Addons Pro CVE-2026-4001, verify product options, review WooCommerce orders, and inspect the site after a critical plugin update.

WordPress.org added a temporary 24-hour cooldown before plugin and theme releases flow through auto-updates. Here is what site owners, agencies, and hosts should do.

CIFSwitch CVE-2026-46243 is a high-severity Linux local privilege escalation affecting CIFS client configurations. Patch kernels, reboot hosts, and review TrueNAS and hosting exposure.

CISA added SolarWinds Serv-U CVE-2026-28318 to KEV on June 5, 2026. Update to Serv-U 15.5.4 Hotfix 1 or the current fixed SolarWinds build.

Patch CVE-2026-48837 by updating Unlimited Elements for Elementor to 2.0.9 or newer. WordPress.org currently lists version 2.0.10.

CISA added Mirasvit Full Page Cache Warmer CVE-2026-45247 to KEV. Magento 2 stores should update to 1.11.12 or newer, or disable the module until patched.

CISA added Oracle WebLogic Server CVE-2024-21182 to KEV on June 1, 2026. Patch affected WebLogic 12.2.1.4.0 and 14.1.1.0.0 systems and restrict T3/IIOP exposure.

CISA added Android Framework CVE-2025-48595 to KEV after Google flagged limited targeted exploitation. Check June 2026 Android patch levels on business and admin devices.