CVE-2026-81789

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.

  • Published Sep 10, 2026
  • CVSS 8.6 high
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-81789 at the National Vulnerability Database