CVE-2026-16940: Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress-plugin/custom-fields-for-woocommerceto a version that resolves this vulnerability.Fixed in 1.5.1Patch before 1.5.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16940?
CVE-2026-16940 has a risk score of 89, indicating a high severity level due to its potential for unauthorized file deletion.
How do I fix CVE-2026-16940?
To fix CVE-2026-16940, you should update the Custom Fields for WooCommerce plugin to version 1.5.1 or later.
What type of vulnerability is CVE-2026-16940?
CVE-2026-16940 is a path traversal vulnerability that allows for unauthenticated arbitrary file deletion.
What files can be affected by CVE-2026-16940?
CVE-2026-16940 can potentially allow deletion of critical files such as wp-config.php.
Who is affected by CVE-2026-16940?
Any WordPress site using the Custom Fields for WooCommerce plugin version prior to 1.5.1 is at risk from CVE-2026-16940.