Impact
Improper limitation of pathname to a restricted directory allows the plugin to delete arbitrary files on the server. An attacker who can manipulate the deletion API could remove critical system files, compromising data integrity and availability. The weakness is identified as path traversal (CWE-22).
Affected Systems
Quantumcloud KBx Pro Ultimate plugin versions earlier than 8.0.5, including 7.9.8 and older, are vulnerable. The flaw applies to the global WordPress installation where the plugin is active. No other vendors or products are listed.
Risk and Exploitability
With a CVSS score of 7.7 and an EPSS score of less than 1 percent, the risk is moderate to high, but exploitation likelihood is low. The vulnerability is not yet listed in CISA KEV, suggesting no known widespread attacks. If an attacker can trigger the deletion function—likely through the plugin’s web interface—they could delete arbitrary files, subject to the server’s permission model.
OpenCVE Enrichment
EUVD