Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce
CVE-2026-81789
8.6HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-81789?
A security flaw exists in Advanced Product Fields Extended for WooCommerce versions up to 3.1.6 that allows unauthenticated users to delete arbitrary files. This vulnerability can potentially lead to data loss and disruption of service, making it critical for website owners using this plugin to ensure they are on the latest version to safeguard against this threat.
Affected Version(s)
Advanced Product Fields Extended for WooCommerce <= 3.1.6
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program