PPOM for WooCommerce <= 34.0.10 - Unauthenticated Path Traversal to Arbitrary File Move via File Upload Field Names
- ID
- WPSEC-2026-0677
- Plugin
- PPOM – Product Addons & Custom Fields for WooCommerce (woocommerce-product-addon)
- Affected
- all versions before 34.0.11
- Remediation
- Update to 34.0.11 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-22
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- PPOM for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 34.0.10. The plugin stored the file names of file upload fields from the shopper's add-to-cart request without validating them, and later joined them onto the upload directory to move each file into the order's folder at checkout. This makes it possible for unauthenticated attackers, on servers whose PHP build resolves '..' path segments before the file system does (such as thread-safe or Windows builds), to move arbitrary files out of their location, such as wp-config.php, which can lead to site takeover. On other servers the move fails.
References
- https://wpsec.com/vuln/WPSEC-2026-0677/
- https://plugins.svn.wordpress.org/woocommerce-product-addon/tags/34.0.11/
- https://wordpress.org/plugins/woocommerce-product-addon/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS