What is CVE-2026-16940?
This critical vulnerability in the Custom Fields WordPress plugin prior to version 1.5.1 allows unauthenticated users to delete arbitrary files on the server (such as wp-config.php) due to lack of user-supplied file path validation, potentially leading to a full site takeover. Immediate update to version 1.5.1 or above is strongly recommended.
Azərbaycanca: Bu kritik boşluq Custom Fields WordPress pluqininin 1.5.1-dən əvvəlki versiyalarında fayl yolunun yoxlanılmaması səbəbindən autentifikasiya olunmamış istifadəçilərə serverdə ixtiyari faylları (məsələn, wp-config.php) silməyə imkan verir ki, bu da saytın tamamilə ələ keçirilməsi ilə nəticələnə bilər. Dərhal pluqini 1.5.1 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the Custom Fields plugin are affected by CVE-2026-16940?
This critical vulnerability affects versions of the Custom Fields WordPress plugin prior to 1.5.1.
What can an unauthenticated attacker do by exploiting CVE-2026-16940?
An unauthenticated attacker can delete arbitrary files on the server, such as wp-config.php, due to lack of user-supplied file path validation, potentially leading to a full site takeover.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.