← Back to browse · API

CVE-2026-16940

Severity
CRITICAL
CVSS
10.0
EPSS
0.00399
Risk score
40.14
CISA KEV
No
PoC
No
Published
2026-08-05
Modified
2026-08-06
First seen
2026-08-06
Aliases
EUVD-2026-53110, GHSA-M93V-54X2-539C
Products
Unknown:Custom Fields 0 <1.5.1
Sources
nvd CVE-2026-16940
euvd EUVD-2026-53110

Description

The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.

References