PPOM for WooCommerce <= 34.0.10 - Unauthenticated Path Traversal to Arbitrary File Move via File Upload Field Names

High 8.1 CWE-22Fixed in 34.0.11
ID
WPSEC-2026-0677
Plugin
PPOM – Product Addons & Custom Fields for WooCommerce (woocommerce-product-addon)
Affected
all versions before 34.0.11
Remediation
Update to 34.0.11 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-22
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
PPOM for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 34.0.10. The plugin stored the file names of file upload fields from the shopper's add-to-cart request without validating them, and later joined them onto the upload directory to move each file into the order's folder at checkout. This makes it possible for unauthenticated attackers, on servers whose PHP build resolves '..' path segments before the file system does (such as thread-safe or Windows builds), to move arbitrary files out of their location, such as wp-config.php, which can lead to site takeover. On other servers the move fails.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0