CVE-2026-16940 PUBLISHED

Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal

Assigner: WPScan
Reserved: 24.07.2026 Published: 05.08.2026 Updated: 05.08.2026

The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.

Product Status

Vendor Unknown
Product Custom Fields
Versions Default: unaffected
  • affected from 0 to 1.5.1 (excl.)

Credits

  • Mike Gozdiskowski finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE