CVE-2026-19089
Received Received - Intake

Unauthenticated File Upload RCE in WooCommerce Product Input Fields

Vulnerability report for CVE-2026-19089, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: WPScan

Description

The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
woocommerce product_input_fields_for_woocommerce to 2.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin 'Product Input Fields for WooCommerce' before version 2.0.2. When the 'accepted-types' setting is left empty, the plugin does not validate uploaded file types, allowing all files to be accepted. This enables unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution if the server does not enforce directory access rules.

Detection Guidance

Check if the Product Input Fields for WooCommerce plugin is installed and verify its version. If it is below 2.0.2, the system is vulnerable. Look for unexpected or suspicious file uploads in directories managed by WooCommerce.

Impact Analysis

Unauthenticated attackers could exploit this flaw to upload malicious files to your server, such as web shells or scripts. If your server does not restrict access to uploaded files, these could be executed remotely, compromising your system integrity, data confidentiality, and availability.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and confidentiality. A successful exploit may result in data breaches, triggering legal penalties, reputational damage, and compliance violations.

Mitigation Strategies

Update the Product Input Fields for WooCommerce plugin to version 2.0.2 or later immediately. Disable file uploads if not required or restrict uploads to specific trusted file types.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19089. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart