Impact
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before version 1.1.8 does not protect its file‑deletion routine; the only gatekeeping mechanism is a nonce that is not bound to user authentication. Anonymous attackers can discover a valid nonce and use it to delete any file that has been staged in the plugin’s upload directory, leading to irreversible loss of customers’ pending order attachments.
Affected Systems
This vulnerability impacts WordPress sites that have installed the Drag and Drop Multiple File Upload for WooCommerce plugin on any version earlier than 1.1.8. Site administrators who have not applied the 1.1.8 update remain exposed.
Risk and Exploitability
The vulnerability is exploitable by unauthenticated users who can obtain a valid nonce; no privilege escalation or network restrictions are needed. The EPSS score is unavailable, and the flaw is not listed in the CISA KEV catalog, but the lack of authentication for a destructive action presents a high‑severity risk. An attacker could delete critical attachments for pending orders, undermining order integrity and potentially exposing customers to fraud or service disruption.
OpenCVE Enrichment