CRITICAL
9.1 CVE-2026-104801 Published 10 Oct 2026
WordPress PPOM Plugin Arbitrary File Deletion Vulnerability
Worried this affects your website?
The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function.
This affects all versions up to, and including, 34.0.10 and can be exploited by unauthenticated attackers. The issue allows attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
- Affected versions: all versions up to and including 34.0.10.
- Attackers are unauthenticated.
- Deleting files such as wp-config.php can lead to remote code execution.
- The relocated file is moved byte-identically into the publicly accessible wp-content/uploads/ppom_files/confirmed/ directory, resulting in arbitrary file read for any web-readable file.
Reference: CVE-2026-104801 on NVD
← Back to Security News