Executive brief
The WooCommerce File Approval plugin is a WordPress extension that manages file uploads and approvals for an e-commerce store. An unauthenticated attacker can exploit this vulnerability to delete arbitrary files from the affected website, potentially destroying critical data, configuration files, and application code, causing severe operational disruption and data loss.
Technical details
This vulnerability is an unauthenticated arbitrary file deletion flaw in WooCommerce File Approval plugin versions 10.7 and earlier. The vulnerability stems from broken access control (OWASP A1) that allows an attacker to submit a request without valid authentication to trigger file deletion operations. The vulnerability is network-reachable and requires no prior authentication or user interaction. An attacker can delete any file accessible to the web server process, including WordPress core files, plugin files, configuration files, and user-uploaded content. As of the advisory date, no official patch is available; Patchstack has issued a mitigation rule to block exploitation attempts.
Affected products
- WooCommerce File Approval <=10.7
Timeline
- 2026-08-24: disclosed: Public disclosure via Patchstack
- 2026-07-11: other: Vulnerability reported by Jamaal ahmed