Arbitrary File Deletion in PPOM Plugin for WooCommerce by WordPress
CVE-2026-104801

9.1CRITICAL

What is CVE-2026-104801?

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is susceptible to arbitrary file deletion due to inadequate file path validation in the rename_files function affecting all versions up to and including 34.0.10. This vulnerability allows unauthenticated attackers to delete critical files on the server, potentially enabling remote code execution if they manage to delete sensitive files like wp-config.php. Additionally, the manipulated files are relocated to the publicly accessible wp-content/uploads/ppom_files/confirmed/ directory, facilitating unauthorized access to any web-readable file on the server.

Affected Version(s)

PPOM – Product Addons & Custom Fields for WooCommerce 0 <= 34.0.10

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

whatm
.