PPOM Product Addons for WooCommerce Arbitrary File Deletion
PPOM Product Addons for WooCommerce allows arbitrary file deletion via insufficient path validation in rename_files. Affects versions up to 34.0.10. CVSS 9.1. Fix: 34.0.11.
- Vendor
- NovaBolt
- Product
- PPOM – Product Addons & Custom Fields for WooCommerce
- CVSS
- 9.1
- EPSS (exploit probability)
- 0.8%
- Status
- patched
- Published
The PPOM Product Addons and Custom Fields for WooCommerce plugin had an arbitrary file deletion vulnerability in all versions up to and including 34.0.10.
The flaw is in the rename_files function. The function does not enforce path constraints before acting on an attacker-supplied file path, which allows a request to specify a target file outside the plugin’s intended directory scope. Any file on the server that the web server process has permission to delete is reachable.
Arbitrary file deletion is rated lower than RCE but remains a serious capability for an attacker. Deleting configuration files can disrupt application functionality, potentially in a way that triggers a default-insecure fallback. Deleting log files before or after an intrusion can complicate forensic investigation. On WordPress, deleting core files can force a reinstall that creates a configuration window.
The fix is in version 34.0.11. Update through the WordPress dashboard or with wp plugin update woocommerce-product-addon.
In the same disclosure batch: CVE-2026-103889 (3D Product Configurator RCE, CVSS 9.8) and CVE-2026-104803 (WPCOM Member authentication bypass, CVSS 9.8). Patch in that order for highest-risk-first coverage. See the full article for full remediation steps.
For ongoing WordPress plugin security coverage, see the WordPress topic hub.
