SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-28171

HIGH · CVSS 8.6 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

WooCommerce File Approval versions up to 10.7 are vulnerable to an unauthenticated arbitrary file deletion flaw, allowing attackers to delete files without authentication. This vulnerability poses a significant risk as it can lead to data loss and disruption of service for affected e-commerce platforms. Organizations using these versions should prioritize remediation to protect their systems and maintain operational integrity.

CVE
CVE-2026-28171
Severity
HIGH
CVSS
8.6
EPSS
0.34%

Original NVD Description

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.