WordPress Plugin Vulnerabilities

Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal

Description

The plugin does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.

Proof of Concept

Affects Plugins

References

Classification

Type
TRAVERSAL
OWASP top 10
CWE

Miscellaneous

Original Researcher
Mike Gozdiskowski
Submitter
Mike Gozdiskowski
Verified
Yes

Timeline

Publicly Published
2026-07-27 (about 9 days ago)
Added
2026-07-27 (about 8 days ago)
Last Updated
2026-08-04 (about 9 hours ago)

Other