WordPress Plugin Vulnerabilities
Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle
Description
The plugin does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
FILE DELETION
OWASP top 10
CWE
CVSS
Miscellaneous
Submitter
Real_King_Engine (ISAL FRAMEWORK)
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-30 (about 28 days ago)
Added
2026-07-30 (about 28 days ago)
Last Updated
2026-07-30 (about 28 days ago)