AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16940

CRITICAL · CVSS 10 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Custom Fields WordPress plugin prior to version 1.5.1 is vulnerable due to inadequate validation of user-supplied file paths, enabling unauthenticated users to delete critical files on the server, including wp-config.php. This flaw poses a significant risk of complete site compromise. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-16940
Severity
CRITICAL
CVSS
10
EPSS
0.40%
WordPress

Original NVD Description

The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.