WordPress Plugin Vulnerabilities

Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle

Description

The plugin does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.

Proof of Concept

Affects Plugins

References

Classification

Type
FILE DELETION
CWE

Miscellaneous

Submitter
Real_King_Engine (ISAL FRAMEWORK)
Verified
Yes

Timeline

Publicly Published
2026-07-30 (about 28 days ago)
Added
2026-07-30 (about 28 days ago)
Last Updated
2026-07-30 (about 28 days ago)

Other