CVE-2026-16940 | Custom Fields Plugin up to 1.5.0 on WordPress wp-config.php path traversal

SecurityVulns

A vulnerability was found in Custom Fields Plugin up to 1.5.0 on WordPress. It has been rated as critical. The affected element is an unknown function of the file wp-config.php. This manipulation causes path traversal.

The identification of this vulnerability is CVE-2026-16940. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More