CVE-2026-16940
Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal
CVSS Score
10.0
EPSS Score
0.2%
EPSS Percentile
6th
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.
| Vendor | unknown |
| Product | custom fields |
| Published | Aug 5, 2026 |
| Last Updated | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown custom fields
Be the first to know when new critical vulnerabilities affecting unknown custom fields are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Custom Fields
0 < 1.5.1
References
Credits
Mike Gozdiskowski WPScan