Impact
The Support Board WordPress plugin contains an insufficient file path validation flaw in the sb_file_delete function that allows an unauthenticated attacker to delete arbitrary files on the server. This abuse can lead to remote code execution when critical files such as wp-config.php are removed, as the attacker can subsequently place malicious code.
Affected Systems
Affected systems include the Schiocco Support Board plugin for WordPress versions 3.8.0 and earlier. These versions run on any WordPress site that has the plugin installed and has not applied the latest security update.
Risk and Exploitability
This vulnerability has a CVSS score of 9.8 and an EPSS of 3%, indicating high severity and a moderate likelihood of exploitation. It is not currently listed in the CISA KEV catalog. Attackers can exploit this unauthenticated weakness using the sb_file_delete endpoint, or by chaining with the separate CVE-2025‑4855 vulnerability, giving them full control over files on the server.
OpenCVE Enrichment
EUVD