Impact
A Cross‑Site Request Forgery flaw in the sminozzi WP Tools WordPress plugin allows an attacker to delete arbitrary files on the web server. The weakness is strengthened by an underlying path traversal issue in the plugin’s file handling routine, enabling the attacker to target any file within the plugin’s installation directory or beyond. Successful exploitation results in loss of data, exposure of sensitive content, and could facilitate further compromise by removing critical files.
Affected Systems
The vulnerability affects the WP Tools plugin provided by sminozzi for WordPress, from the earliest available releases up through version 5.18. Administrators who keep an outdated copy of WP Tools (≤5.18) are at risk, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 7.4 signals a high severity, while the EPSS score of less than 1% indicates a very low current exploitation probability, and the flaw is not listed in CISA’s KEV catalog. The most likely attack vector is a CSRF request originating from a malicious web page that tricks a privileged user into visiting a forged URL. The attacker does not need elevated privileges on the file system beyond normal web‑app permissions; the plugin’s own file permissions are sufficient. Once the request is accepted, the plugin deletes the targeted file without further confirmation.
OpenCVE Enrichment
EUVD