What is CVE-2026-16054?
A critical vulnerability in the 'Drag and Drop Multiple File Upload' plugin for WooCommerce (versions prior to 1.1.8) allows unauthenticated users to obtain a valid nonce, bypassing the only control on its file-deletion routine. This flaw enables anonymous attackers to irreversibly delete files from the plugin's upload directory. Immediate update to version 1.1.8 or later is strongly recommended.
Azərbaycanca: WooCommerce üçün 'Drag and Drop Multiple File Upload' adlı WordPress plugin-ində (1.1.8-dən əvvəlki versiyalarda) autentifikasiya olmamış istifadəçilərin fayl silmək üçün tələb olunan nonce dəyərini əldə etməsinə imkan verən kritik boşluq aşkarlanıb. Bu boşluq anonim hücumçulara upload qovluğunda saxlanılan faylları geri dönməz şəkildə silməyə imkan yaradır. Plugin-i dərhal ən son versiyaya (1.1.8+) yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What type of users can exploit CVE-2026-16054?
Unauthenticated (anonymous) users can exploit this vulnerability.
What should be done to protect against CVE-2026-16054?
Immediately update the plugin to version 1.1.8 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.