Impact
The PPOM – Product Addons & Custom Fields for WooCommerce plugin allows unauthenticated attackers to delete arbitrary files on the WordPress server due to missing validation of file paths in the rename_files function. Deleting a critical file such as wp-config.php can directly lead to arbitrary code execution, while moving the file to a publicly accessible location also permits arbitrary file reads of any web‑readable file. The weakness is a classic directory traversal flaw (CWE‑22).
Affected Systems
This vulnerability is present in every installation of the PPOM plugin released up to and including version 34.0.10. The affected product is the PPOM – Product Addons & Custom Fields for WooCommerce plugin developed by ThemeIsle.
Risk and Exploitability
The CVSS score of 9.1 reflects the high severity of this issue. No EPSS information is available, and the vulnerability is not listed in the CISA KEV catalog, though the absence of these metrics does not reduce the intrinsic risk. Attackers can invoke the flaw by sending a specially crafted POST request containing a ‘ppom[fields][<data_name>][n][org]’ parameter that refers to an arbitrary file path. Because the plugin then renames the file without sanitizing the path, any file readable by the web process can be targeted, making the threat vector largely an unauthenticated HTTP request.
OpenCVE Enrichment