Unauthenticated Arbitrary File Deletion and Read in PPOM Plugin for WooCommerce
The PPOM - Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file deletion and reading via improper path validation in the rename_files function, facilitating potential RCE.
CVE search metadata
CVE search record: CVE-2026-104801. Severity: critical. CVSS: 9.1. KEV: no. Product: PPOM – Product Addons & Custom Fields for WooCommerce (<= 34.0.10). Brief: Unauthenticated Arbitrary File Deletion and Read in PPOM Plugin for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ppom-plugin-vulnerability/
The PPOM - Product Addons & Custom Fields for WooCommerce plugin for WordPress is affected by a critical vulnerability (CVE-2026-104801) in versions up to and including 34.0.10. The vulnerability resides within the rename_files function, which suffers from insufficient file path validation. This flaw allows unauthenticated remote attackers to trigger the deletion of arbitrary files on the underlying server. By targeting sensitive configuration files such as wp-config.php, an attacker can force a site to reset its configuration or become unavailable, often a precursor to remote code execution (RCE) via site takeover. Additionally, the function moves the targeted file to a publicly accessible directory (wp-content/uploads/ppom_files/confirmed/), enabling unauthorized arbitrary file reading of any file accessible to the web server user. This vulnerability represents a significant risk to the integrity and confidentiality of WordPress installations utilizing the affected plugin.
Impact
Successful exploitation allows unauthenticated attackers to gain unauthorized access to sensitive files or cause site-wide denial of service. By deleting critical components like wp-config.php, attackers can bypass security controls or reconfigure the environment to facilitate RCE. The vulnerability impacts all WordPress sites running PPOM plugin versions 34.0.10 or earlier.
Recommendation
- Immediately update the PPOM - Product Addons & Custom Fields for WooCommerce plugin to the latest version released after 34.0.10.
- Audit web server logs for suspicious POST requests targeting the endpoint responsible for file renaming or processing within the PPOM plugin path.
- Restrict external access to the /wp-content/uploads/ppom_files/confirmed/ directory via web server configuration to prevent unauthorized retrieval of relocated files.
Immediate actions
Upgrade PPOM - Product Addons & Custom Fields for WooCommerce to version > 34.0.10
Mitigations
Restrict access to /wp-content/uploads/ppom_files/confirmed/ at the web server level
CVE-2026-104801