A vulnerability classified as critical has been found in YITH WooCommerce Product Add-Ons Plugin up to 4.29.0 on WordPress. This affects an unknown function. This manipulation causes sql injection. This vulnerability is tracked as CVE-2026-42383 . The attack is possible to be carried out remotely. No exploit exists.