AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16054

CRITICAL · CVSS 9.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Drag and Drop Multiple File Upload for WooCommerce plugin prior to version 1.1.8 is vulnerable to unauthenticated file deletion due to insufficient nonce protection, enabling anonymous attackers to delete files from the upload directory. This flaw can lead to the irreversible loss of customer order attachments, significantly impacting e-commerce operations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16054
Severity
CRITICAL
CVSS
9.1
EPSS
0.27%
WordPress

Original NVD Description

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.