CVE-2026-66480: Yith Woocommerce Product Add-Ons

Medium severity, CVSS 5.3.

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in YITH YITH WooCommerce Product Add-Ons allows Retrieve Embedded Sensitive Data. This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.34.0.

Affected products

  • Yith Yith Woocommerce Product Add-Ons: up to and including 4.34.0

Published 2026-10-10. Last modified 2026-10-10.