Sceawere
Vulnerability Detail
CVE-2026-104801UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PPOM Arbitrary File Deletion Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 3h ago
- Vendor
- themeisle
- Product
- PPOM – Product Addons & Custom Fields for WooCommerce
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The relocated file is moved byte-identically into the publicly accessible wp-content/uploads/ppom_files/confirmed/ directory, meaning the attack also results in arbitrary file read for any web-readable file on the server.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-10-10T07:16:40.560Z",
"pubdate": "2026-10-10T07:16:40.560Z",
"executiveSummary": "The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress contains a critical vulnerability involving improper file path validation within the rename_files function.\nThis vulnerability allows unauthenticated remote attackers to delete arbitrary files on the underlying filesystem by manipulating input parameters.\nThe flaw also facilitates unauthorized arbitrary file read operations, as the mechanism moves target files into the publicly accessible wp-content/uploads/ppom_files/confirmed/ directory.\nThe impact is severe, as the deletion of critical configuration files like wp-config.php can lead to a complete site takeover or facilitate remote code execution by forcing the WordPress setup routine or exposing sensitive database credentials.\nThe vulnerability affects all versions up to and including 34.0.10, necessitating immediate remediation to prevent exploitation.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient input sanitization and path validation within the rename_files function of the PPOM – Product Addons & Custom Fields for WooCommerce plugin. The function fails to implement a robust allowlist or path traversal check on user-supplied file paths, allowing an attacker to reference sensitive system or application files outside of the intended directory scope.\nThe exploitation flow initiates when an unauthenticated actor submits a crafted request to the vulnerable endpoint that triggers the rename_files function. By manipulating parameters processed by this function, an attacker can specify an arbitrary absolute or relative path to a target file. Because the application logic does not validate if the requested file path resides within the authorized uploads directory, the function proceeds to perform a filesystem operation on the attacker-specified file.\nThe primary impact is a dual-threat: file deletion and information disclosure. When the function processes the request, it executes a move or rename operation that relocates the target file into the publicly accessible directory located at wp-content/uploads/ppom_files/confirmed/. If the attacker targets a sensitive file such as wp-config.php, the file is relocated, effectively removing it from its original configuration path, which renders the site unreachable and triggers a re-installation state. Concurrently, the file becomes accessible via a direct HTTP request to the new location within the uploads directory, exposing sensitive credentials including database passwords and secret keys.\nSuccessful exploitation of this vulnerability results in arbitrary file deletion, which can lead to a complete service outage or, when combined with subsequent application configuration state changes, potential remote code execution. The vulnerability is exploitable by unauthenticated attackers without any special privileges, as the vulnerable function is exposed via a public-facing entry point. The lack of validation on the destination move path combined with the exposure of the destination directory creates a high-severity security risk, enabling both system-level destructive actions and critical data theft."
}