PT-2026-69383 · WordPress · Product Input Fields For Woocommerce

·

CVE-2026-19089

·

Published

2026-08-10

·

Updated

2026-08-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Product Input Fields for WooCommerce versions prior to 2.0.2
Description An issue exists where the plugin fails to validate uploaded file types when the accepted-types setting is left empty. This configuration, which is advertised in the documentation as a way to accept all files, allows unauthenticated attackers to upload arbitrary files. This can lead to remote code execution on servers that do not enforce directory access rules.
Recommendations Update Product Input Fields for WooCommerce to version 2.0.2 or later. Avoid leaving the accepted-types setting empty to prevent the upload of arbitrary files.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19089

Affected Products

Product Input Fields For Woocommerce