{
 "id": "WPSEC-2026-0677",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0677/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0677/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0677/index.md",
 "title": "PPOM for WooCommerce <= 34.0.10 - Unauthenticated Path Traversal to Arbitrary File Move via File Upload Field Names",
 "description": "The Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 34.0.10. The plugin stored the file names of file upload fields from the shopper's add-to-cart request without validating them, and later joined them onto the upload directory to move each file into the order's folder at checkout. This makes it possible for unauthenticated attackers, on servers whose PHP build resolves '..' path segments before the file system does (such as thread-safe or Windows builds), to move arbitrary files out of their location, such as wp-config.php, which can lead to site takeover. On other servers the move fails.",
 "plugin": {
  "slug": "woocommerce-product-addon",
  "name": "PPOM for WooCommerce",
  "full_name": "PPOM – Product Addons & Custom Fields for WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/woocommerce-product-addon/",
  "advisories_url": "https://wpsec.com/vuln/plugin/woocommerce-product-addon/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/woocommerce-product-addon"
 },
 "type": "TRAVERSAL",
 "cwe": [
  "CWE-22"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 8.1,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "34.0.11",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 34.0.11"
  ]
 },
 "introduced_in": null,
 "fixed_in": "34.0.11",
 "remediation": "Update to 34.0.11 or later.",
 "fix_released": "2026-10-07T20:44:43+00:00",
 "published": "2026-10-08T21:46:21+00:00",
 "updated": "2026-10-08T07:40:39.560407+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0677/",
  "https://plugins.svn.wordpress.org/woocommerce-product-addon/tags/34.0.11/",
  "https://wordpress.org/plugins/woocommerce-product-addon/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/woocommerce-product-addon",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}