CVE-2026-104801
Received Received - Intake

Arbitrary File Deletion in PPOM for WooCommerce

Vulnerability report for CVE-2026-104801, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The relocated file is moved byte-identically into the publicly accessible wp-content/uploads/ppom_files/confirmed/ directory, meaning the attack also results in arbitrary file read for any web-readable file on the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
themeisle PPOM – Product Addons & Custom Fields for WooCommerce 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the PPOM plugin for WordPress. It allows unauthenticated attackers to delete arbitrary files on the server due to insufficient validation in the rename_files function. This can lead to remote code execution if critical files like wp-config.php are deleted. Attackers can also read any web-readable file as the deleted file is moved to a publicly accessible directory.

Detection Guidance

Check for unauthorized file deletions or modifications in the wp-content/uploads/ppom_files/confirmed/ directory. Monitor server logs for suspicious activity related to the PPOM plugin or WordPress file operations.

Impact Analysis

If exploited, this vulnerability can allow attackers to delete important files on your server, potentially causing website downtime or data loss. It may also enable them to read sensitive files, leading to unauthorized access to confidential information. In severe cases, it could result in complete server compromise through remote code execution.

Compliance Impact

This vulnerability can lead to unauthorized file deletion and data exposure, violating GDPR's integrity and confidentiality requirements. For HIPAA, it risks unauthorized access to protected health information, potentially breaching security rules. Compliance failures may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Immediately update the PPOM plugin to the latest version if available. If not, disable the plugin until a patch is released. Review and restrict file permissions on the wp-content/uploads/ directory to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104801. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart