Impact
This vulnerability allows an attacker to delete files on the server by exploiting a path traversal flaw in the Paid Videochat Turnkey Site plugin, which implements the incorrect restriction of a pathname to a protected directory. The flaw—classified as CWE‑22—enables arbitrary deletion of sensitive files, potentially leading to data loss, service disruption, and loss of integrity for the affected WordPress site.
Affected Systems
The flaw affects the videowhisper Paid Videochat Turnkey Site plugin for WordPress in all releases from the earliest available versions through version 7.2.12 inclusive. Users running any of these versions are at risk.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity impact, yet the current EPSS score of less than 1% and absence from the CISA KEV list suggest a low likelihood of exploitation at present. The attack vector is most likely an HTTP request crafted by an attacker to reach the plugin’s deletion endpoint, from which the path traversal can be exercised. Despite the low exploitation probability, the potential for significant data loss warrants timely remediation.
OpenCVE Enrichment
EUVD