CyberRota Analysis
AI-GeneratedThe Custom Fields WordPress plugin prior to version 1.5.1 is vulnerable due to inadequate validation of user-supplied file paths, enabling unauthenticated users to delete critical files on the server, including wp-config.php. This flaw poses a significant risk of complete site compromise. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.
CVE
CVE-2026-16940
Severity
CRITICAL
CVSS
10
EPSS
0.40%
WordPress
Original NVD Description
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.