ZeroHour

CVE-2026-81789

moderate

Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81789 is an unauthenticated arbitrary file deletion vulnerability (path traversal, CWE-22) in the Advanced Product Fields Extended for WooCommerce WordPress plugin, affecting all versions up to and including 3.1.6. Because the vulnerable code is reachable through network-facing WooCommerce/plugin endpoints without requiring a login, a remote attacker can submit traversal paths that cause the plugin to delete an arbitrary file on the server. The immediate impact is to site availability, which the CVSS 8.6 score reflects (high availability impact, changed scope), and in WordPress, removal of critical files such as wp-config.php can additionally open the door to full site compromise, though no published exploit chain describes that escalation. Any WordPress site running the plugin at version 3.1.6 or earlier as part of a WooCommerce store is affected. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known.

What to do: Update Advanced Product Fields Extended for WooCommerce to the newest release (any version above 3.1.6) as soon as practical. As an interim mitigation, block or rate-limit unauthenticated requests to the plugin's endpoints at the WAF and verify the integrity of core files such as wp-config.php if you suspect tampering. Because no public PoC exists yet, patching now closes the window before exploit details typically emerge.

Affected
StudioWombat Advanced Product Fields Extended for WooCommerce (WordPress plugin)<= 3.1.6
Estimated exposure
moderatelikely on the order of a few thousand to roughly 10,000 WooCommerce storefronts — No active-install count was provided in the source data, but the Advanced Product Fields product line is a niche WooCommerce customization add-on whose WordPress.org listings have historically been in the ~10k active-install range — a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.

Ecosystems
WordPress, E-commerce
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.