Impact
The vulnerability is a path traversal flaw that arises because the Advanced Product Fields Extended for WooCommerce plugin does not properly limit a pathname to a restricted directory. By submitting a specially crafted file path, an attacker could cause the plugin to delete or otherwise modify files that lie outside the intended data directory. This could lead to loss of data, site corruption, or further exploitation of the WordPress installation.
Affected Systems
WordPress sites that have the Advanced Product Fields Extended for WooCommerce plugin at version 3.1.6 or earlier are affected. The product, released by Studio Wombat, can be found under the name Advanced Product Fields Extended for WooCommerce in all such installations.
Risk and Exploitability
The CVSS score of 8.6 places this flaw in the high-severity category, while the EPSS score of <1% indicates a low probability of exploitation. The CVE description does not specify whether authentication is required to reach the vulnerable code, so the exact attack vector—remote or requiring logged‑in access—is not confirmed. If the functionality is exposed through the WordPress web interface, an attacker could potentially send a crafted request that triggers file deletion, but the precise conditions remain unspecified. The vulnerability is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment