Skip to content
CVE Disclosure · WordPress Plugin Ecosystem

CVE-2026-3594

Riaxe Product Customizer

Information disclosure

CVSS5.3
SeverityMedium
ClassInformation disclosure
TrackWordPress Plugin Ecosystem

Summary

CVE-2026-3594 is a medium-severity vulnerability (CVSS 5.3) affecting Riaxe Product Customizer. The issue is classified as Information disclosure, part of the WordPress Plugin Ecosystem disclosure track on this site.

References

Authoritative sources and PoC material:

Disclosure

Reporter
Kai Aizen (snailsploit)
Coordination
Vendor + MITRE/NVD
Status
Disclosed · CVE assigned · entry public on NVD
Track
WordPress Plugin Ecosystem

About this writeup

Detailed exploitation analysis, root-cause walkthrough, and remediation guidance for this finding live in the PoC repository. For broader methodology see services and research.

disclosure contextall 74 cves →
Author
Kai Aizen
Independent Adversarial · Research group. 74 published CVEs, 5 Linux kernel mainline patches, creator of AATMF / P.R.O.M.P.T / SEF, author of Adversarial Minds.
Quick facts
ID
CVE-2026-3594
Product
Riaxe Product Customizer
Severity
5.3 · Medium
Class
Information disclosure
References: NVD · MITRE · snailsploit CVE ledger
Frequently asked

CVE-2026-3594 — questions & answers

What is CVE-2026-3594?

CVE-2026-3594 is a disclosed vulnerability (Information disclosure) in Riaxe Product Customizer, coordinated through the standard CVE process by independent security researcher Kai Aizen.

Am I affected by CVE-2026-3594?

You are affected if your environment runs an unpatched version of Riaxe Product Customizer. Check the upstream advisory or NVD record for the precise affected version range, then verify against your deployed version.

How do I fix CVE-2026-3594?

Upgrade Riaxe Product Customizer to the version that includes the upstream fix referenced in the NVD record. If an immediate upgrade is not possible, apply the mitigation guidance from the vendor advisory and restrict exposure of the affected surface area.

What is the impact of CVE-2026-3594?

CVSS 5.3 · Medium. The vulnerability class is Information disclosure; consult the NVD and vendor advisory for vector details, exploitation prerequisites, and observed impact.

Where can I find authoritative references?

NVD record at https://nvd.nist.gov/vuln/detail/CVE-2026-3594, the MITRE CVE record at https://www.cve.org/CVERecord?id=CVE-2026-3594, and the vendor's security advisory page.