Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce
CVE-2026-81789

8.6HIGH

What is CVE-2026-81789?

A security flaw exists in Advanced Product Fields Extended for WooCommerce versions up to 3.1.6 that allows unauthenticated users to delete arbitrary files. This vulnerability can potentially lead to data loss and disruption of service, making it critical for website owners using this plugin to ensure they are on the latest version to safeguard against this threat.

Affected Version(s)

Advanced Product Fields Extended for WooCommerce <= 3.1.6

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.