The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules.
CVE-2026-19089
NONE
EPSS 0.20%
Updated Aug 10, 2026
WordPress
CVE Details
CVE ID
CVE-2026-19089
Published Date
Aug 10, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.20%
Likelihood of exploitation in next 30 days
Percentile:
10.4th percentile (higher than 10.4% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory