CVE-2026-16940
Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.
| Vendor | unknown |
| Product | custom fields |
| Published | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown custom fields
Be the first to know when new unknown vulnerabilities affecting unknown custom fields are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Custom Fields
0 < 1.5.1
References
Credits
Mike Gozdiskowski WPScan