Custom Fields
Custom Fields adds and manages custom fields for WordPress content and other site data.
Custom Fields (custom-fields) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 10.
custom-fieldsCVE-2026-16940: Custom Fields permits unauthenticated arbitrary file deletion
Custom Fields before 1.5.1 accepts an unauthenticated, user-controlled filesystem path and deletes the referenced file without constraining it to an intended directory. An attacker can delete arbitrary server files such as wp-config.php; removing critical configuration can disrupt the site and may enable takeover during recovery or reinstallation. This unscored record received deeper review because unauthenticated arbitrary file deletion is directly chainable. The CNA does not disclose the endpoint, action, parameter or deletion function.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-16940
Custom Fields permits unauthenticated arbitrary file deletion
Custom Fields before 1.5.1 accepts an unauthenticated, user-controlled filesystem path and deletes the referenced file without constraining it to an intended directory. An attacker can delete arbitrary server files such as wp-config.php; removing critical configuration can disrupt the site and may enable takeover during recovery or reinstallation. This unscored record received deeper review because unauthenticated arbitrary file deletion is directly chainable. The CNA does not disclose the endpoint, action, parameter or deletion function.
|
1.5.1 |
CVE10.0
NVDPending
|