Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-16940: WooCommerce Custom Fields < 1.5.1: Unauthenticated File Deletion Risk
CVE-2026-16940 · published 1 month ago
Summary
A security flaw in WooCommerce Custom Fields versions before 1.5.1 allows anyone to delete any file on the server, potentially giving them control of the entire website. This is a serious issue because it could allow hackers to access sensitive information or take over the site. Update to version 1.5.1 or later to fix this issue.
What to do
- Update unknown custom fields to version 1.5.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | custom fields | < 1.5.1 |
Original advisory text
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-confi...
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.
References
- https://wpscan.com/vulnerability/a315a6ac-3ffb-4735-92ca-6e85338f8807/ exploit vdb-entry technical-description
Severity
10.0
Critical
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published5 Aug 2026
Updated3 Sep 2026
First seen5 Aug 2026
Monitor software like this
Free during beta