Junglewise Threat Intelligence

CVE-2026-81789: Studio Wombat Advanced Product Fields Extended arbitrary file deletion

CVE-2026-81789 · Severity: high · CVSS 8.6 · Published 2026-09-10

Executive brief

Advanced Product Fields Extended is a WordPress plugin that adds custom product field functionality to WooCommerce stores. An unauthenticated attacker can exploit a path traversal vulnerability to delete arbitrary files from the server, potentially disabling the website and destroying critical business data.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in the Advanced Product Fields Extended for WooCommerce plugin versions 3.1.6 and earlier. The vulnerability allows unauthenticated attackers to delete arbitrary files on the web server by manipulating file path parameters. This is a critical arbitrary file deletion vulnerability that requires no authentication or user interaction. An attacker can delete essential WordPress files, database backups, configuration files, and other critical assets, resulting in site unavailability and potential data loss. The issue has been patched in version 3.1.7.

Affected products

  • Studio Wombat Advanced Product Fields Extended for WooCommerce through 3.1.6

Timeline

  • 2026-09-09: disclosed: Published by Patchstack
  • 2026-09-09: patched: Fixed in version 3.1.7

References