← WordPress Vulnerabilities
WordPress security by component

Custom Fields

Custom Fields adds and manages custom fields for WordPress content and other site data.

Custom Fields (custom-fields) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 10.

Plugin slug: custom-fields

CVE-2026-16940: Custom Fields permits unauthenticated arbitrary file deletion

Custom Fields before 1.5.1 accepts an unauthenticated, user-controlled filesystem path and deletes the referenced file without constraining it to an intended directory. An attacker can delete arbitrary server files such as wp-config.php; removing critical configuration can disrupt the site and may enable takeover during recovery or reinstallation. This unscored record received deeper review because unauthenticated arbitrary file deletion is directly chainable. The CNA does not disclose the endpoint, action, parameter or deletion function.

PublishedAug 05, 2026
Known safe version1.5.1
Published vulnerabilities for custom-fields
Safe version
Aug 05, 2026 CVE-2026-16940
Custom Fields permits unauthenticated arbitrary file deletion
Custom Fields before 1.5.1 accepts an unauthenticated, user-controlled filesystem path and deletes the referenced file without constraining it to an intended directory. An attacker can delete arbitrary server files such as wp-config.php; removing critical configuration can disrupt the site and may enable takeover during recovery or reinstallation. This unscored record received deeper review because unauthenticated arbitrary file deletion is directly chainable. The CNA does not disclose the endpoint, action, parameter or deletion function.
1.5.1
CVE10.0
NVDPending