Impact
The flaw allows an attacker to delete arbitrary files from the server without authentication. By sending a crafted request to the WordPress site, the attacker can specify any path and remove files, including configuration files, themes, plugins or other critical assets. This can lead to data loss, downtime, or further compromise if the deleted files are required for secure operation.
Affected Systems
WordPress installations running the Advanced Product Fields Extended for WooCommerce plugin version 3.1.6 or earlier. The affected product is provided by Maarten B under the name Advanced Product Fields Extended for WooCommerce.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is considered high severity. No EPSS score is available, and it is not listed in the CISA KEV catalog, but the lack of authentication requirements means the attack vector is remote via the web interface. An attacker can exploit this simply by crafting a HTTP request to the plugin’s endpoint with a path parameter, bypassing any permission checks and triggering file deletion.
OpenCVE Enrichment