Tag
#Arbitrary File Deletion
Grav CMS Path Traversal Vulnerability in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
A path traversal vulnerability in Grav CMS's MediaUploadTrait::deleteFile() allows authenticated users with media management permissions to delete arbitrary files on the server. This vulnerability has a CVSS score of 7.1 and is classified as CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').
CVE-2026-19991: Arbitrary File Deletion Vulnerability in UsersWP Plugin for WordPress
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70. This vulnerability allows authenticated attackers with Subscriber-level access and above to delete arbitrary files on the affected site's server, including critical files like wp-config.php. The vulnerability has a CVSS score of 8.1, indicating a high severity. Immediate patching is recommended to prevent potential exploitation.
Critical Vulnerability in SigmaForms Pro – AI Generated Forms Plugin for WordPress: Arbitrary File Deletion
A critical vulnerability, CVE-2026-78657, with a CVSS score of 9.8, was discovered in the SigmaForms Pro – AI Generated Forms plugin for WordPress. This vulnerability allows unauthenticated attackers to delete arbitrary files on the server due to insufficient file path validation in the delete_submission_files function. This can lead to remote code execution when a critical file, such as wp-config.php, is deleted. The vulnerability affects all versions up to and including 1.4.11 of the plugin.
Critical Vulnerability in Podlove Podcast Publisher Plugin for WordPress: CVE-2026-16099
The Podlove Podcast Publisher plugin for WordPress, versions up to and including 4.5.3, is vulnerable to arbitrary file deletion due to insufficient file path validation. This allows authenticated attackers with contributor-level access to delete arbitrary files, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.8 and is classified as CWE-502 Deserialization. Immediate patching is recommended.
Critical Vulnerability in File Manager Plugin for WordPress: CVE-2026-15991
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in versions 6.0 - 6.9. Authenticated attackers with subscriber-level access can read and delete arbitrary files, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.8 and is not actively exploited. Immediate patching or mitigation is recommended.
CVE-2026-9843: Arbitrary File Deletion Vulnerability in Database for Contact Form 7, WPforms, Elementor forms Plugin
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation. This allows unauthenticated attackers to delete arbitrary files, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.1 and affects all versions up to 1.5.1. Immediate patching is recommended.