Impact
The Home Villas WordPress theme contains a flaw in the wp_rem_cs_widget_file_delete function that performs insufficient file path validation. This permits an attacker with authenticated Subscriber‑level or higher access to delete arbitrary files on the web server, exposing the victim to the possibility of remote code execution should a critical file such as wp‑config.php be removed. The weakness is a path traversal issue, categorised as CWE‑22.
Affected Systems
The vulnerability applies to the Chimp Group Home Villas Real Estate WordPress Theme in all releases up to and including version 2.8. Any WordPress installation using these theme files is affected.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity, and the EPSS score of <1% indicates a low likelihood of exploitation in the wild. Because the flaw requires authentication at the Subscriber level or higher, an attacker needs valid credentials but can then delete arbitrary files. The vulnerability is not currently listed in the CISA KEV catalogue, suggesting limited known exploitation, yet its impact warrants timely remediation.
OpenCVE Enrichment
EUVD