SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-81789

HIGH · CVSS 8.6 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Advanced Product Fields Extended for WooCommerce versions up to 3.1.6 are vulnerable to unauthenticated arbitrary file deletion, allowing attackers to delete files on the server without authentication. This could lead to significant disruption of services and potential data loss for affected e-commerce sites. Organizations using these versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-81789
Severity
HIGH
CVSS
8.6
EPSS
0.36%

Original NVD Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.