Description
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before version 1.1.8 does not protect its file‑deletion routine; the only gatekeeping mechanism is a nonce that is not bound to user authentication. Anonymous attackers can discover a valid nonce and use it to delete any file that has been staged in the plugin’s upload directory, leading to irreversible loss of customers’ pending order attachments.

Affected Systems

This vulnerability impacts WordPress sites that have installed the Drag and Drop Multiple File Upload for WooCommerce plugin on any version earlier than 1.1.8. Site administrators who have not applied the 1.1.8 update remain exposed.

Risk and Exploitability

The vulnerability is exploitable by unauthenticated users who can obtain a valid nonce; no privilege escalation or network restrictions are needed. The EPSS score is unavailable, and the flaw is not listed in the CISA KEV catalog, but the lack of authentication for a destructive action presents a high‑severity risk. An attacker could delete critical attachments for pending orders, undermining order integrity and potentially exposing customers to fraud or service disruption.

Generated by OpenCVE AI on August 6, 2026 at 07:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Drag and Drop Multiple File Upload for WooCommerce plugin to version 1.1.8 or later.
  • If an immediate update is not possible, restrict write permissions for the upload directory so that only authenticated users can delete files.
  • Regularly audit the upload directory for unexpected deletions and restore any lost files from backups.
  • Enable logging of deletion attempts and review logs for suspicious activity.

Generated by OpenCVE AI on August 6, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 06 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.
Title Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-06T06:00:09.540Z

Reserved: 2026-07-17T12:00:16.861Z

Link: CVE-2026-16054

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T07:30:16Z

Weaknesses