Feed/CVE-2026-16054
CVE-2026-16054CRITICALCVSS 9.1

CVE-2026-16054

Published Aug 6, 2026·Updated Aug 6, 2026

NVD Description

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free