Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-16940: WooCommerce Custom Fields < 1.5.1: Unauthenticated File Deletion Risk

CVE-2026-16940 · published 1 month ago
Summary

A security flaw in WooCommerce Custom Fields versions before 1.5.1 allows anyone to delete any file on the server, potentially giving them control of the entire website. This is a serious issue because it could allow hackers to access sensitive information or take over the site. Update to version 1.5.1 or later to fix this issue.

What to do
  • Update unknown custom fields to version 1.5.1 or later.
Affected software
VendorProductAffected versions
unknown custom fields < 1.5.1
Original advisory text
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-confi...
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.
References
Severity
10.0 Critical
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published5 Aug 2026
Updated3 Sep 2026
First seen5 Aug 2026
Sources
CVE-2026-16940 · MITRE
Monitor software like this
Free during beta