Unauthenticated File Deletion Vulnerability in WooCommerce File Approval Plugin
CVE-2026-28171

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 August 2026

What is CVE-2026-28171?

The WooCommerce File Approval plugin, versions up to 10.7, contains a vulnerability that allows unauthenticated users to delete arbitrary files from the server. This could lead to potential data loss and exploitation by malicious actors, as improper validation of user inputs can permit unauthorized deletion actions. Webmasters using this plugin should take immediate action to secure their sites and update to the latest version to mitigate these risks.

Affected Version(s)

WooCommerce File Approval <= 10.7

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jamaal ahmed | Patchstack Bug Bounty Program
.