PT-2026-67986 · WordPress · Custom Fields
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Custom Fields WordPress plugin versions prior to 1.5.1
Description
An issue exists where the plugin fails to validate a user-supplied file path before performing a deletion operation. This allows unauthenticated users to delete arbitrary files on the server, such as the
wp-config.php file, potentially leading to a full site takeover.Recommendations
Update Custom Fields WordPress plugin to version 1.5.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Custom Fields