External risk intelligence

PPOM WooCommerce Plugin Arbitrary File Deletion and Read Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-104801

The vulnerability exists in a WordPress plugin for WooCommerce. WordPress sites with e-commerce functionality are typically public-facing web applications designed to be accessed by users over the internet. As an unauthenticated endpoint within a publicly accessible web application, this component is highly likely to be internet-facing in standard deployments.

Path Traversal

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the PPOM – Product Addons & Custom Fields for WooCommerce plugin, which affects WordPress websites. This issue allows for the deletion and potential reading of arbitrary files on the server, which could lead to the execution of malicious code. The main concern is confirming the relevance and exposure of this plugin within our environment.

  • Plugin flaw allows deleting/reading any file.
  • Critical risk if any of our sites use this plugin.
  • Confirm if we use this e-commerce plugin.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a malicious request to a vulnerable WordPress site. This request targets the PPOM plugin's file handling functionality, specifically the `rename_files` function, which lacks proper path validation. By manipulating this function, an attacker can trick the plugin into deleting arbitrary files on the server. The deletion of critical files, such as configuration files, could lead to a complete site compromise, and the arbitrary file read capability allows attackers to gain unauthorized access to sensitive information.

  • Entry condition: Publicly accessible WordPress site.
  • Trigger point: Malicious request to the vulnerable plugin.
  • Resulting risk: Arbitrary file deletion and read.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow attackers to delete or read arbitrary files on a WordPress server, potentially leading to the compromise of sensitive configuration files or the execution of malicious code. The issue arises from insufficient validation of file paths within the plugin's file handling functions.

  • Arbitrary file deletion and read.
  • Exploits insufficient file path validation.
  • Could lead to code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The PPOM plugin for WooCommerce is susceptible to arbitrary file deletion, which could lead to remote code execution or arbitrary file reads. The primary responsibility for addressing this typically falls to the application owner or the platform team managing the WordPress instance. The first practical step is to identify all instances of the affected plugin, confirm their accessibility and business criticality, and then establish ownership for remediation planning.

  • Application or platform teams should own this issue.
  • Verify plugin presence and public exposure.
  • Plan risk-based remediation with vendor.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the PPOM – Product Addons & Custom Fields for WooCommerce plugin?

It is a WordPress plugin designed to extend WooCommerce by adding custom fields and product options to online storefronts. These tools allow store owners to collect additional information or provide choices to customers during the checkout process. Because it integrates directly into the e-commerce workflow, it often handles data and files uploaded by visitors.

What does CWE-22 mean in the context of CVE-2026-104801?

CWE-22 refers to Improper Limitation of a Pathname to a Restricted Directory, often called Path Traversal. In this vulnerability, the plugin fails to check if a requested file path is outside of its intended, safe directory. Because the system does not properly validate this path, an attacker can trick the plugin into accessing, deleting, or moving files anywhere on the server's file system.

How can an attacker trigger this vulnerability?

An attacker sends a specifically crafted request to the plugin that interacts with the vulnerable rename_files function. By manipulating input parameters, they can force the server to perform actions on files it should not touch. Simply browsing the site or performing standard e-commerce actions as a legitimate customer does not trigger this; it requires an intentional, malicious request aimed at the plugin's file-handling logic.

Why is this considered high risk for internet-facing sites?

According to Halo Surface Signal, this plugin is typically used on public-facing e-commerce websites. Because the vulnerability allows unauthenticated access, any user on the internet can attempt to send malicious requests to the server without needing a login. This means the flaw is exposed directly to the public web, significantly increasing the potential for unauthorized file deletion or data access.

What should I do if I use this plugin?

Your first step is to perform an inventory of your WordPress environments to confirm where the PPOM plugin is installed. Once you have identified all instances, determine which sites are internet-facing and assess their business criticality. Engage with your application or platform teams to plan the removal of the plugin or the application of vendor-provided security updates to mitigate the risk.

References