Description
The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The relocated file is moved byte-identically into the publicly accessible wp-content/uploads/ppom_files/confirmed/ directory, meaning the attack also results in arbitrary file read for any web-readable file on the server.
Published: 2026-10-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The PPOM – Product Addons & Custom Fields for WooCommerce plugin allows unauthenticated attackers to delete arbitrary files on the WordPress server due to missing validation of file paths in the rename_files function. Deleting a critical file such as wp-config.php can directly lead to arbitrary code execution, while moving the file to a publicly accessible location also permits arbitrary file reads of any web‑readable file. The weakness is a classic directory traversal flaw (CWE‑22).

Affected Systems

This vulnerability is present in every installation of the PPOM plugin released up to and including version 34.0.10. The affected product is the PPOM – Product Addons & Custom Fields for WooCommerce plugin developed by ThemeIsle.

Risk and Exploitability

The CVSS score of 9.1 reflects the high severity of this issue. No EPSS information is available, and the vulnerability is not listed in the CISA KEV catalog, though the absence of these metrics does not reduce the intrinsic risk. Attackers can invoke the flaw by sending a specially crafted POST request containing a ‘ppom[fields][<data_name>][n][org]’ parameter that refers to an arbitrary file path. Because the plugin then renames the file without sanitizing the path, any file readable by the web process can be targeted, making the threat vector largely an unauthenticated HTTP request.

Generated by OpenCVE AI on October 10, 2026 at 08:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the PPOM plugin to the latest available version (34.0.11 or newer) or remove the plugin if it is not required.
  • If an upgrade is not immediately possible, restrict access to the plugin’s configuration and file‑handling endpoints to authenticated administrators only, or disable the file deletion functionality if the plugin provides a setting.
  • Verify that critical files such as wp-config.php are not writable by the web server process and that the uploads directory is not publicly writable; backup configuration files before applying changes.

Generated by OpenCVE AI on October 10, 2026 at 08:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The relocated file is moved byte-identically into the publicly accessible wp-content/uploads/ppom_files/confirmed/ directory, meaning the attack also results in arbitrary file read for any web-readable file on the server.
Title PPOM <= 34.0.10 - Unauthenticated Arbitrary File Deletion via 'ppom[fields][<data_name>][n][org]' Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:11.824Z

Reserved: 2026-10-02T13:14:55.098Z

Link: CVE-2026-104801

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:40.560

Modified: 2026-10-10T07:16:40.560

Link: CVE-2026-104801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')