The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Drag and Drop Multiple File Upload plugin for WooCommerce contains a critical authentication bypass vulnerability where unauthenticated attackers can obtain valid nonces—security tokens meant to prevent unauthorized actions—that gate the file deletion functionality. This allows anonymous users to delete files in the plugin's upload directory, irreversibly destroying customer order attachments and disrupting business operations. Any WooCommerce store using this plugin before version 1.1.8 is vulnerable, directly impacting order integrity, customer trust, and potential compliance violations if attachments contain sensitive data. The 9.1 CVSS score reflects the ease of exploitation and severe business impact with no authentication barrier.
While this CVE currently has zero matching Casky skills, practitioners investigating similar vulnerabilities would leverage Casky's 754 MITRE ATT&CK-mapped security skills and Claude's extended reasoning to identify attack patterns around credential and authentication bypass (T1110, T1078 class techniques). The detection approach would focus on observing unauthorized nonce generation and redemption patterns—monitoring for repeated delete requests from unauthenticated sources, unexpected nonce issuance in web logs, and bulk file deletions without corresponding authenticated sessions. A practitioner using Casky would correlate suspicious API calls to the deletion endpoint with absence of valid user sessions, identify the broken access control flaw in code review, and map remediation to enforcing proper nonce validation tied to authenticated users rather than exposing tokens universally.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-16054. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation