Arbitrary File Deletion in PPOM Plugin for WooCommerce by WordPress
CVE-2026-104801
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104801?
The PPOM β Product Addons & Custom Fields for WooCommerce plugin for WordPress is susceptible to arbitrary file deletion due to inadequate file path validation in the rename_files function affecting all versions up to and including 34.0.10. This vulnerability allows unauthenticated attackers to delete critical files on the server, potentially enabling remote code execution if they manage to delete sensitive files like wp-config.php. Additionally, the manipulated files are relocated to the publicly accessible wp-content/uploads/ppom_files/confirmed/ directory, facilitating unauthorized access to any web-readable file on the server.
Affected Version(s)
PPOM β Product Addons & Custom Fields for WooCommerce 0 <= 34.0.10