{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpressppom_product_addons_custom_fields_for_woocommerce/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:ppom_product_addons_custom_fields_for_woocommerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-104801"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PPOM – Product Addons \u0026 Custom Fields for WooCommerce (\u003c= 34.0.10)"],"_cs_severities":["critical"],"_cs_tags":["web-application","wordpress","vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe PPOM - Product Addons \u0026amp; Custom Fields for WooCommerce plugin for WordPress is affected by a critical vulnerability (CVE-2026-104801) in versions up to and including 34.0.10. The vulnerability resides within the rename_files function, which suffers from insufficient file path validation. This flaw allows unauthenticated remote attackers to trigger the deletion of arbitrary files on the underlying server. By targeting sensitive configuration files such as wp-config.php, an attacker can force a site to reset its configuration or become unavailable, often a precursor to remote code execution (RCE) via site takeover. Additionally, the function moves the targeted file to a publicly accessible directory (wp-content/uploads/ppom_files/confirmed/), enabling unauthorized arbitrary file reading of any file accessible to the web server user. This vulnerability represents a significant risk to the integrity and confidentiality of WordPress installations utilizing the affected plugin.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain unauthorized access to sensitive files or cause site-wide denial of service. By deleting critical components like wp-config.php, attackers can bypass security controls or reconfigure the environment to facilitate RCE. The vulnerability impacts all WordPress sites running PPOM plugin versions 34.0.10 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the PPOM - Product Addons \u0026amp; Custom Fields for WooCommerce plugin to the latest version released after 34.0.10.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious POST requests targeting the endpoint responsible for file renaming or processing within the PPOM plugin path.\u003c/li\u003e\n\u003cli\u003eRestrict external access to the /wp-content/uploads/ppom_files/confirmed/ directory via web server configuration to prevent unauthorized retrieval of relocated files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T07:50:35Z","date_published":"2026-10-10T07:50:35Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ppom-plugin-vulnerability/","summary":"The PPOM - Product Addons \u0026 Custom Fields for WooCommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file deletion and reading via improper path validation in the rename_files function, facilitating potential RCE.","title":"Unauthenticated Arbitrary File Deletion and Read in PPOM Plugin for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-10-ppom-plugin-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:ppom_product_addons_custom_fields_for_woocommerce:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}