CVE-2026-16940

CVE-2026-16940: Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal

Vendor Unknown
Product Custom Fields
Published August 5, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.

Key dates

02Disclosure timeline

August 5, 2026 CVE published
August 6, 2026 Record updated