CVE-2026-81789
moderateUnauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce
CVE-2026-81789 is an unauthenticated arbitrary file deletion vulnerability (path traversal, CWE-22) in the Advanced Product Fields Extended for WooCommerce WordPress plugin, affecting all versions up to and including 3.1.6. Because the vulnerable code is reachable through network-facing WooCommerce/plugin endpoints without requiring a login, a remote attacker can submit traversal paths that cause the plugin to delete an arbitrary file on the server. The immediate impact is to site availability, which the CVSS 8.6 score reflects (high availability impact, changed scope), and in WordPress, removal of critical files such as wp-config.php can additionally open the door to full site compromise, though no published exploit chain describes that escalation. Any WordPress site running the plugin at version 3.1.6 or earlier as part of a WooCommerce store is affected. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known.
What to do: Update Advanced Product Fields Extended for WooCommerce to the newest release (any version above 3.1.6) as soon as practical. As an interim mitigation, block or rate-limit unauthenticated requests to the plugin's endpoints at the WAF and verify the integrity of core files such as wp-config.php if you suspect tampering. Because no public PoC exists yet, patching now closes the window before exploit details typically emerge.
| StudioWombat Advanced Product Fields Extended for WooCommerce (WordPress plugin) | <= 3.1.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.