CVE-2026-16054

CVE-2026-16054: Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle

Vendor Unknown
Product Drag and Drop Multiple File Upload for WooCommerce
Published August 6, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.

Key dates

02Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated