CVE-2026-16940 | Custom Fields Plugin up to 1.5.0 on WordPress wp-config.php path traversal
A vulnerability was found in Custom Fields Plugin up to 1.5.0 on WordPress. It has been rated as critical. The affected element is an unknown function of the file wp-config.php. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-16940. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More